Vulnerability index

Browse CVEs

30 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.0 CVE-2025-53690 KEVEPSS 31% Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This iss… Experience Commerce after 9.0 Fix from $2,3002025-09-03 CRITICAL 9.8 CVE-2025-53693EPSS 14% Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Experience Manager (XM), Siteco… Experience Commerce 10.4+ Fix from $2,3002025-09-03 HIGH 8.8 CVE-2025-53691 Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Remote Code Execution (… Experience Commerce 10.4+ Fix from $1,9502025-09-03 HIGH 7.5 CVE-2025-53694EPSS 6% Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (… Experience Commerce 10.4+ Fix from $1,9502025-09-03 HIGH 8.8 CVE-2025-34510EPSS 17% Sitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10.0 through 10.4 are affected … Experience Commerce 10.4+ Fix from $1,9502025-06-17 HIGH 8.8 CVE-2025-34511EPSS 16% Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an u… Experience Commerce 10.4+ Fix from $1,9502025-06-17 HIGH 7.5 CVE-2025-34509EPSS 55% Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 0119… Experience Commerce 10.4+ Fix from $1,9502025-06-17 HIGH 7.5 CVE-2024-46938EPSS 46% An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 … Experience Commerce after 10.4 Fix from $1,9502024-09-15 CRITICAL 9.8 CVE-2023-35813EPSS 87% Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3. Experience Commerce after 10.3 Fix from $2,3002023-06-17 HIGH 8.8 CVE-2023-33652 Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /siteco… Experience Platform No fix yet Fix from $1,9502023-06-06 HIGH 8.8 CVE-2023-33653 Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /Applic… Experience Platform No fix yet Fix from $1,9502023-06-06 HIGH 7.5 CVE-2023-33651 An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initial Release… Experience Commerce after 10.3 Fix from $1,9502023-06-06 CRITICAL 9.8 CVE-2023-27068 Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationResult.asp… Experience Platform 10.2+ Fix from $2,3002023-05-23 HIGH 7.5 CVE-2023-27067 Directory Traversal vulnerability in Sitecore Experience Platform through 10.2 allows remote attackers to download arbitrary files via crafted comman… Experience Platform after 10.2 Fix from $1,9502023-05-22 MEDIUM 6.5 CVE-2023-27066 Directory Traversal vulnerability in Site Core Experience Platform 10.2 and earlier allows authenticated remote attackers to download arbitrary files… Experience Platform after 10.2 Fix from $1,6002023-05-22 HIGH 7.2 CVE-2023-26262 An issue was discovered in Sitecore XP/XM 10.3. As an authenticated Sitecore user, a unrestricted language file upload vulnerability exists the can l… Experience Manager 10.3+ Fix from $1,9502023-03-14 CRITICAL 9.8 CVE-2021-42237 KEVEPSS 98% Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remot… Experience Platform Mitigation only Fix from $2,3002021-11-05 HIGH 8.8 CVE-2021-38366 Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve remote code execution b… Sitecore after 10.1 Fix from $1,9502021-08-12 MEDIUM 6.1 CVE-2019-11198 Multiple cross-site scripting (XSS) vulnerabilities in Sitecore CMS 9.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML v… Cms after 9.0.1 Fix from $1,6002019-08-05 MEDIUM 5.4 CVE-2019-13493 In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user can modify the uploaded f… Experience Platform No fix yet Fix from $1,6002019-07-17 HIGH 8.8 CVE-2019-11080EPSS 14% Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. An authenticated user … Experience Platform 9.1.1+ Fix from $1,9502019-06-06 CRITICAL 9.8 CVE-2019-9874 KEVEPSS 84% Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allo… Cms after 8.2 Fix from $2,3002019-05-31 HIGH 8.8 CVE-2019-9875 KEVEPSS 14% Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sendi… Cms after 9.1 Fix from $1,9502019-05-31 CRITICAL 9.8 CVE-2019-12440 The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious commands and code via the Sitecore R… Rocks 2.1.149+ Fix from $2,3002019-05-29 HIGH 7.5 CVE-2018-7669EPSS 17% An issue was discovered in Sitecore Sitecore.NET 8.1 rev. 151207 Hotfix 141178-1 and above. The 'Log Viewer' application is vulnerable to a directory… Sitecore.net No fix yet Fix from $1,9502018-04-27 MEDIUM 5.4 CVE-2017-11439 In Sitecore 8.2, there is reflected XSS in the shell/Applications/Tools/Run Program parameter. Cms No fix yet Fix from $1,6002017-07-19 MEDIUM 6.1 CVE-2017-9356 Sitecore.NET 7.1 through 7.2 has a Cross Site Scripting Vulnerability via the searchStr parameter to the /Search-Results URI. Sitecore.net No fix yet Fix from $1,6002017-06-23 MEDIUM 6.7 CVE-2017-5965 The package manager in Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to execute arbitrary ASP code by creating a ZIP archive… Crm No fix yet Fix from $1,6002017-05-23 MEDIUM 6.1 CVE-2016-8855 Cross-Site Scripting (XSS) in "/sitecore/client/Applications/List Manager/Taskpages/Contact list" in Sitecore Experience Platform 8.1 rev. 160519 (8.… Experience Platform No fix yet Fix from $1,6002017-03-19 MEDIUM 6.8 CVE-2009-4367EPSS 6% The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote attackers … Staging Module after 5.4.0 Fix from $1,6002009-12-21