Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.0
CVE-2025-53690 KEVEPSS 31%
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This iss…
Experience Commerce
after 9.0
CRITICAL 9.8
CVE-2025-53693EPSS 14%
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Experience Manager (XM), Siteco…
Experience Commerce
10.4+
HIGH 8.8
CVE-2025-53691
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Remote Code Execution (…
Experience Commerce
10.4+
HIGH 7.5
CVE-2025-53694EPSS 6%
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (…
Experience Commerce
10.4+
HIGH 8.8
CVE-2025-34510EPSS 17%
Sitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10.0 through 10.4 are affected …
Experience Commerce
10.4+
HIGH 8.8
CVE-2025-34511EPSS 16%
Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an u…
Experience Commerce
10.4+
HIGH 7.5
CVE-2025-34509EPSS 55%
Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 0119…
Experience Commerce
10.4+
HIGH 7.5
CVE-2024-46938EPSS 46%
An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 …
Experience Commerce
after 10.4
CRITICAL 9.8
CVE-2023-35813EPSS 87%
Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.
Experience Commerce
after 10.3
HIGH 8.8
CVE-2023-33652
Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /siteco…
Experience Platform
No fix yet
HIGH 8.8
CVE-2023-33653
Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /Applic…
Experience Platform
No fix yet
HIGH 7.5
CVE-2023-33651
An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initial Release…
Experience Commerce
after 10.3
CRITICAL 9.8
CVE-2023-27068
Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationResult.asp…
Experience Platform
10.2+
HIGH 7.5
CVE-2023-27067
Directory Traversal vulnerability in Sitecore Experience Platform through 10.2 allows remote attackers to download arbitrary files via crafted comman…
Experience Platform
after 10.2
MEDIUM 6.5
CVE-2023-27066
Directory Traversal vulnerability in Site Core Experience Platform 10.2 and earlier allows authenticated remote attackers to download arbitrary files…
Experience Platform
after 10.2
HIGH 7.2
CVE-2023-26262
An issue was discovered in Sitecore XP/XM 10.3. As an authenticated Sitecore user, a unrestricted language file upload vulnerability exists the can l…
Experience Manager
10.3+
CRITICAL 9.8
CVE-2021-42237 KEVEPSS 98%
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remot…
Experience Platform
Mitigation only
HIGH 8.8
CVE-2021-38366
Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve remote code execution b…
Sitecore
after 10.1
MEDIUM 6.1
CVE-2019-11198
Multiple cross-site scripting (XSS) vulnerabilities in Sitecore CMS 9.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML v…
Cms
after 9.0.1
MEDIUM 5.4
CVE-2019-13493
In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user can modify the uploaded f…
Experience Platform
No fix yet
HIGH 8.8
CVE-2019-11080EPSS 14%
Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. An authenticated user …
Experience Platform
9.1.1+
CRITICAL 9.8
CVE-2019-9874 KEVEPSS 84%
Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allo…
Cms
after 8.2
HIGH 8.8
CVE-2019-9875 KEVEPSS 14%
Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sendi…
Cms
after 9.1
CRITICAL 9.8
CVE-2019-12440
The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious commands and code via the Sitecore R…
Rocks
2.1.149+
HIGH 7.5
CVE-2018-7669EPSS 17%
An issue was discovered in Sitecore Sitecore.NET 8.1 rev. 151207 Hotfix 141178-1 and above. The 'Log Viewer' application is vulnerable to a directory…
Sitecore.net
No fix yet
MEDIUM 5.4
CVE-2017-11439
In Sitecore 8.2, there is reflected XSS in the shell/Applications/Tools/Run Program parameter.
Cms
No fix yet
MEDIUM 6.1
CVE-2017-9356
Sitecore.NET 7.1 through 7.2 has a Cross Site Scripting Vulnerability via the searchStr parameter to the /Search-Results URI.
Sitecore.net
No fix yet
MEDIUM 6.7
CVE-2017-5965
The package manager in Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to execute arbitrary ASP code by creating a ZIP archive…
Crm
No fix yet
MEDIUM 6.1
CVE-2016-8855
Cross-Site Scripting (XSS) in "/sitecore/client/Applications/List Manager/Taskpages/Contact list" in Sitecore Experience Platform 8.1 rev. 160519 (8.…
Experience Platform
No fix yet
MEDIUM 6.8
CVE-2009-4367EPSS 6%
The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote attackers …
Staging Module
after 5.4.0