Vulnerabilities
31 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-53690 | Unauthenticated ViewState Deserialization RCE in Sitecore XM/XP CVE-2025-53690 is a critical (CVSS 9.0) deserialization-of-untrusted-data flaw (CWE-502) in Sitecore Experience Manager (XM) and Experience Platform (XP) through version 9.0 that enables unauthenticated code injection. Public threat reporting (Google Cloud/Mandiant) and news coverage tie the flaw to ASP.NET ViewState deserialization performed using exposed (default or leaked) ASP.NET machine keys, so a remote attacker who can reach a Sitecore site can submit a crafted, signed ViewState payload that is deserialized server-side, resulting in remote code execution. A successful unauthenticated attacker gains arbitrary code execution on the web server with the scope-changed (S:C) impact of high confidentiality, integrity and availability loss. Organizations running internet-facing Sitecore XM/XP deployments — including Experience Commerce and Managed Cloud deployments — are in scope. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-09-04, and reporting links the activity to a China-linked APT (UAT-8837) targeting North American critical infrastructure. Do: Apply Sitecore's security updates to all affected XM/XP deployments (through 9.0) and follow the vendor's mitigations as required by CISA KEV/BOD 22-01, or discontinue use if patching is not possible. Per the public reporting, rotate any exposed or default ASP.NET machineKey values (e.g., in web.config) on internet-facing Sitecore servers, since exposed machine keys enable the ViewState deserialization attacks. Inventory internet-exposed Sitecore instances and review them for signs of compromise. | 9.0 | 51% | KEV PoC |
| largetens of thousands of internet-exposed Sitecore deployments (order of magnitude ~10^4–10^5) | |
| CVE-2025-53693 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experien Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Cache Poisoning.This issue affects Sitecore Experience Manager (XM): from 9.0 through 9.3, from 10.0 through 10.4; Experience Platform (XP): from 9.0 through 9.3, from 10.0 through 10.4. NVD description · AI analysis pending | 9.8 group max | 14% | PoC |
| — | |
| CVE-2025-34511 | Unrestricted File Upload RCE in Sitecore PowerShell Extensions (SPE) Sitecore PowerShell Extensions (SPE), a widely installed administrative add-on for Sitecore Experience Manager (XM) and Experience Platform (XP), contains an unrestricted file upload flaw (CWE-434) in all versions through 7.0. A remote attacker with valid low-privileged credentials can send a crafted HTTP request that uploads arbitrary files, such as a webshell, to the web server, which are then executed, yielding remote code execution with high impact on confidentiality, integrity, and availability. Any Sitecore XM, XP, Experience Commerce, or Managed Cloud deployment running the SPE add-on at version 7.0 or earlier is affected, making enterprise CMS operators the primary at-risk population. Exploitation is not yet listed in CISA KEV and no confirmed in-the-wild campaigns are documented, but a public proof-of-concept has been published by WatchTowr, and EPSS assigns a high 22.3% probability of exploitation within 30 days (98th percentile). Researchers have also shown this flaw chained with other Sitecore issues, including a hard-coded credential, to achieve pre-authentication RCE in enterprise deployments. Do: Upgrade Sitecore PowerShell Extensions to a fixed release newer than 7.0 as directed by Sitecore's advisory, prioritizing internet-facing content management and delivery servers. Until patched, restrict access to SPE endpoints (PowerShell services/remoting endpoints) to trusted administrative users with strong authentication. Audit upload directories and web roots for unexpected files or webshells, and confirm the instance is also patched against the related hard-coded-credential Sitecore XP issues researchers chained with this flaw. | 8.8 group max | 22% | PoC |
| largetens of thousands of internet-exposed Sitecore XM/XP/Commerce instances, with a large but unquantified subset running the SPE add-on (exact SPE install count… | |
| CVE-2024-46938 | Unauthenticated Arbitrary File Read in Sitecore XP, XM, and XC 8.0–10.4 Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) contain an information-disclosure flaw (CWE-200) that lets an unauthenticated remote attacker read arbitrary files from the server. The issue is triggered over the network with no authentication, no user interaction, and low attack complexity, per the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N). Successful exploitation yields high-confidence confidentiality impact — exposure of sensitive files such as application configuration and secrets — with no integrity or availability impact. Any organization running the affected versions, spanning 8.0 Initial Release through 10.4 Initial Release, is in scope. The flaw is not yet listed in CISA KEV and no public proof-of-concept is known, but an EPSS of 46.8% (99th percentile) indicates an elevated probability of exploitation within the next 30 days. Do: Apply Sitecore's security patch for your version line, upgrading deployments beyond the affected 10.4 Initial Release baseline; since no specific fixed build is stated in the advisory data, consult the vendor advisory for the exact remediated release per version. Until patched, restrict Sitecore management and content-delivery endpoints to trusted networks and review web/application logs for anomalous file-read requests. Given the high EPSS score, prioritize internet-facing instances and monitor for emerging PoC or in-the-wild exploitation. | 7.5 | 47% |
| largetens of thousands of internet-exposed instances | ||
| CVE-2023-35813 | Multiple Sitecore products allow remote code execution. Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3. NVD description · AI analysis pending | 9.8 | 87% |
| — | ||
| CVE-2023-33652 +1 in the same advisory: …33653 | Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /sitecore/shell/In Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /sitecore/shell/Invoke.aspx. NVD description · AI analysis pending | 8.8 | 2% | PoC |
| — | |
| CVE-2023-33651 | An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initial Release to v13.0 I An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initial Release to v13.0 Initial Release allows attackers to bypass authorization rules. NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2023-27068 | Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationResult.aspx. Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationResult.aspx. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2023-27067 +1 in the same advisory: …27066 | Directory Traversal vulnerability in Sitecore Experience Platform through 10.2 allows remote attackers to download arbitrary files via crafted command to downlo Directory Traversal vulnerability in Sitecore Experience Platform through 10.2 allows remote attackers to download arbitrary files via crafted command to download.aspx NVD description · AI analysis pending | 7.5 group max | 2% | PoC |
| — | |
| CVE-2023-26262 | An issue was discovered in Sitecore XP/XM 10.3. An issue was discovered in Sitecore XP/XM 10.3. As an authenticated Sitecore user, a unrestricted language file upload vulnerability exists the can lead to direct code execution on the content management (CM) server. NVD description · AI analysis pending | 7.2 | 2% | PoC |
| — | |
| CVE-2021-42237 | Unauthenticated Deserialization RCE in Sitecore XP 7.5-8.2 Sitecore Experience Platform (XP) 7.5 Initial Release through 8.2 Update-7 contains an insecure deserialization flaw (CWE-502) that allows unauthenticated remote command execution on the server. An attacker triggers it simply by sending crafted serialized input to an affected Sitecore instance over the network; no authentication, special configuration, or user interaction is required (CVSS 9.8). Successful exploitation yields arbitrary command execution with the privileges of the web application, giving attackers full control of the CMS server to steal data, deploy malware, or pivot into the corporate network. Any organization running the affected Sitecore XP releases is exposed, particularly content management or delivery servers reachable from the internet. The flaw is actively exploited: it was added to CISA's KEV on 2022-03-25 with known ransomware use, EPSS puts the 30-day exploitation probability at 97.9%, and contemporaneous reporting describes access brokers such as 'Gold Melody' selling compromised network access to ransomware operators. Do: Apply updates per vendor instructions: upgrade to a fixed release or install the hotfix Sitecore provided for each affected 7.5-8.2 version, as required by CISA's KEV entry. Prioritize internet-facing Sitecore servers, review logs for signs of exploitation, and restrict network access to Sitecore endpoints as an interim measure, since ransomware operators are known to exploit this flaw. | 9.8 | 98% | KEV ransomware PoC |
| largetens of thousands of internet-exposed Sitecore XP servers worldwide, with the affected subset running 7.5-8.2 | |
| CVE-2021-38366 | Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve remote code execution by visiting Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve remote code execution by visiting an uploaded .aspx file at an admin/Packages URL. NVD description · AI analysis pending | 8.8 | 3% | PoC |
| — | |
| CVE-2019-11198 | Multiple cross-site scripting (XSS) vulnerabilities in Sitecore CMS 9.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Multiple cross-site scripting (XSS) vulnerabilities in Sitecore CMS 9.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) #300583 - List Manager Dashboard module, (2) #307638 - Campaign Creator module, (3) #316994 - Attributes field, (4) I#316995 - Icon Selection module, (5) #317000 - Latitude field, (6) #317000 - Longitude field, (7) #317017 - UploadPackage2.aspx module, (8) #317072 - Context menu, or (9) I#317073 - Insert from Template dialog. NVD description · AI analysis pending | 6.1 | 1% |
| — | ||
| CVE-2019-13493 | In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user can modify the uploaded file extension parameter to inject arbitrary JavaScript. NVD description · AI analysis pending | 5.4 | 2% | PoC |
| — | |
| CVE-2019-11080 | Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. An authenticated user with necessary permissions is able to remotely execute OS commands by sending a crafted serialized object. NVD description · AI analysis pending | 8.8 | 14% | PoC |
| — | |
| CVE-2019-9874 +1 in the same advisory: …9875 | Unauthenticated .NET Deserialization RCE in Sitecore CMS and Experience Platform CVE-2019-9874 is a deserialization flaw (CWE-502) in the Sitecore.Security.AntiCSRF module that lets an unauthenticated attacker run arbitrary code remotely. It is triggered by sending a crafted serialized .NET object in the HTTP POST parameter __CSRFTOKEN, which the module deserializes without validation. Successful exploitation yields full remote code execution with the privileges of the web application, with confidentiality, integrity, and availability all impacted. Users of Sitecore CMS 7.0 through 7.2 and Sitecore Experience Platform (XP) 7.5 through 8.2 are affected. The flaw carries a critical CVSS 3.1 score of 9.8, a very high EPSS score of 83.7%, and was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-26, indicating active exploitation in the wild; ransomware use is currently unknown. Do: Upgrade affected Sitecore CMS (7.0–7.2) and XP (7.5–8.2) deployments to a patched, currently supported release per Sitecore's security guidance, as required by CISA's KEV/BOD 22-01 action for federal agencies. Until patched, restrict network access to vulnerable Sitecore instances and monitor IIS/web logs for unauthenticated POST requests containing oversized or anomalous __CSRFTOKEN values. A public technical advisory with exploitation details is available from Synacktiv, so treat exploitability as confirmed. | 9.8 group max | 84% | KEV PoC |
| largeon the order of tens of thousands of internet-exposed Sitecore CMS/XP deployments (estimated) | |
| CVE-2019-12440 | The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious commands and code via the Sitecore Rocks Hard R The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious commands and code via the Sitecore Rocks Hard Rocks Service. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2018-7669 | An issue was discovered in Sitecore Sitecore.NET 8.1 rev. An issue was discovered in Sitecore Sitecore.NET 8.1 rev. 151207 Hotfix 141178-1 and above. The 'Log Viewer' application is vulnerable to a directory traversal attack, allowing an attacker to access arbitrary files from the host Operating System using a sitecore/shell/default.aspx?xmlcontrol=LogViewerDetails&file= URI. Validation is performed to ensure that the text passed to the 'file' parameter correlates to the correct log file directory. This filter can be bypassed by including a valid log filename and then appending a traditional 'dot dot' style attack. NVD description · AI analysis pending | 7.5 | 17% | PoC |
| — | |
| CVE-2017-11439 +1 in the same advisory: …11440 | In Sitecore 8.2, there is reflected XSS in the shell/Applications/Tools/Run Program parameter. In Sitecore 8.2, there is reflected XSS in the shell/Applications/Tools/Run Program parameter. NVD description · AI analysis pending | 5.4 group max | <1% | PoC ×2 |
| — | |
| CVE-2017-9356 | Sitecore.NET 7.1 through 7.2 has a Cross Site Scripting Vulnerability via the searchStr parameter to the /Search-Results URI. Sitecore.NET 7.1 through 7.2 has a Cross Site Scripting Vulnerability via the searchStr parameter to the /Search-Results URI. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2017-5965 +1 in the same advisory: …5966 | The package manager in Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to execute arbitrary ASP code by creating a ZIP archive in which a The package manager in Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to execute arbitrary ASP code by creating a ZIP archive in which a .asp file has a ..\ in its pathname, visiting sitecore/shell/applications/install/dialogs/Upload%20Package/UploadPackage2.aspx to upload this archive and extract its contents, and visiting a URI under sitecore/ to execute the .asp file. NVD description · AI analysis pending | 6.7 group max | 1% | PoC |
| — | |
| CVE-2016-8855 | Cross-Site Scripting (XSS) in "/sitecore/client/Applications/List Manager/Taskpages/Contact list" in Sitecore Experience Platform 8.1 rev. Cross-Site Scripting (XSS) in "/sitecore/client/Applications/List Manager/Taskpages/Contact list" in Sitecore Experience Platform 8.1 rev. 160519 (8.1 Update-3) allows remote attacks via the Name or Description parameter. This is fixed in 8.2 Update-2. NVD description · AI analysis pending | 6.1 | 2% | PoC ×2 |
| — |