MEDIUM
Sitecore XP 7.5 - 10.2, CMS 7.2, and Managed Cloud XSS
Published Jul 25, 2025
5.1
MEDIUMCVSS 4.0
EPSS 0.65%
Description
A cross-site scripting (XSS) vulnerability exists in Sitecore Experience Platform (XP) 7.5 - 10.2 and CMS 7.2 - 7.2 Update-6 that may allow authenticated Sitecore Shell users to be tricked into executing custom JS code. Managed Cloud Standard customers who run the affected Sitecore Experience Platform / CMS versions are also affected.
Affected products
-
Affected
- ≥ 7.2 Initial Release, ≤ 7.2 Update-6
-
Affected
- ≥ 10.0 Initial Release, ≤ 10.0 Update-3
- ≥ 10.1 Initial Release, ≤ 10.1 Update-2
- 10.2 Initial Release
- ≥ 7.5 Initial Release, ≤ 7.5 Update-2
- ≥ 8.0 Initial Release, ≤ 8.0 Update-7
- ≥ 8.1 Initial Release, ≤ 8.1 Update-3
- ≥ 8.2 Initial Release, ≤ 8.2 Update-7
- ≥ 9.0 Initial Release, ≤ 9.0 Update-2
- ≥ 9.1 Initial Release, ≤ 9.1 Update 1
- 9.2 Initial Release
- 9.3 Initial Release
-
Affected
- n/a
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Sitecore | Content Mangement System (CMS) | unaffected | Affected
|
| Sitecore | Experience Platform | unaffected | Affected
|
| Sitecore | Managed Cloud | unaffected | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-55211 Advisory
- https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1001489 vendor-advisorypatch
- https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1001539 vendor-advisorypatch
- https://www.vulncheck.com/advisories/sitecore-xp-cms-managed-cloud-xss third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-55211 | Advisory | |
| https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1001489 | vendor-advisorypatch | |
| https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1001539 | vendor-advisorypatch | |
| https://www.vulncheck.com/advisories/sitecore-xp-cms-managed-cloud-xss | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jul 25, 2025
Updated Mar 23, 2026
Reserved Jul 24, 2025
Link CVE-2022-4979
CISA Vulnrichment
Updated Jul 25, 2025
Red Hat
No data
GitHub
No data