Sitecore / Experience Platform
21 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-53690 KEV | Sitecore Products ViewState Deserialization Vulnerability | CRITICAL | 9.0 | Sep 3, 2025 |
| CVE-2025-53691 | Sitecore Experience Remote Code Execution through Insecure Deserialization | HIGH | 8.8 | Sep 3, 2025 |
| CVE-2025-53693 | HTML Cache Poisoning through Unsafe Reflections | CRITICAL | 9.8 | Sep 3, 2025 |
| CVE-2025-53694 | Information Disclosure in ItemServices API | HIGH | 7.5 | Sep 3, 2025 |
| CVE-2022-4979 | Sitecore XP 7.5 - 10.2, CMS 7.2, and Managed Cloud XSS | MEDIUM | 5.1 | Jul 25, 2025 |
| CVE-2025-34511 | Sitecore PowerShell Extension RCE via Unrestricted Upload | HIGH | 8.8 | Jun 17, 2025 |
| CVE-2025-34510 | Sitecore XM, XC, and XP Post-Auth RCE via Zip Slip | HIGH | 8.8 | Jun 17, 2025 |
| CVE-2025-34509 | Sitecore XM and XP Hardcoded Credentials | HIGH | 7.5 | Jun 17, 2025 |
| CVE-2024-46938 | An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Re… | HIGH | 7.5 | Sep 15, 2024 |
| CVE-2023-35813 | Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3. | CRITICAL | 9.8 | Jun 17, 2023 |
| CVE-2023-33653 | Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /Applications/Con… | HIGH | 8.8 | Jun 6, 2023 |
| CVE-2023-33652 | Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /sitecore/shell/I… | HIGH | 8.8 | Jun 6, 2023 |
| CVE-2023-33651 | An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initial Release to v13.0… | HIGH | 7.5 | Jun 6, 2023 |
| CVE-2023-27068 | Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationResult.aspx. | CRITICAL | 9.8 | May 23, 2023 |
| CVE-2023-27067 | Directory Traversal vulnerability in Sitecore Experience Platform through 10.2 allows remote attackers to download arbitrary files via crafted command to downl… | HIGH | 7.5 | May 22, 2023 |
| CVE-2023-27066 | Directory Traversal vulnerability in Site Core Experience Platform 10.2 and earlier allows authenticated remote attackers to download arbitrary files via Urlha… | MEDIUM | 6.5 | May 22, 2023 |
| CVE-2023-26262 | An issue was discovered in Sitecore XP/XM 10.3. As an authenticated Sitecore user, a unrestricted language file upload vulnerability exists the can lead to dir… | HIGH | 7.2 | Mar 14, 2023 |
| CVE-2021-42237 KEV | Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command… | CRITICAL | 9.8 | Nov 5, 2021 |
| CVE-2019-13493 | In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user can modify the uploaded file extens… | MEDIUM | 5.4 | Jul 17, 2019 |
| CVE-2019-11080 | Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. An authenticated user with neces… | HIGH | 8.8 | Jun 6, 2019 |
| CVE-2019-9874 KEV | Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unau… | CRITICAL | 9.8 | May 31, 2019 |
| CVE-2016-8855 | Cross-Site Scripting (XSS) in "/sitecore/client/Applications/List Manager/Taskpages/Contact list" in Sitecore Experience Platform 8.1 rev. 160519 (8.1 Update-3… | MEDIUM | 6.1 | Mar 19, 2017 |
Showing 1 to 21 of 21 CVEs