Vulnerability index

Browse CVEs

30 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Experience Commerce CRITICAL 9.0
CVE-2025-53690 KEVEPSS 31%

Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This iss…

Fix: after 9.0
Fix from $2,300 2025-09-03
Experience Commerce CRITICAL 9.8
CVE-2025-53693EPSS 14%

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Experience Manager (XM), Siteco…

Fix: 10.4+
Fix from $2,300 2025-09-03
Experience Commerce HIGH 8.8
CVE-2025-53691

Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Remote Code Execution (…

Fix: 10.4+
Fix from $1,950 2025-09-03
Experience Commerce HIGH 7.5
CVE-2025-53694EPSS 6%

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (…

Fix: 10.4+
Fix from $1,950 2025-09-03
Experience Commerce HIGH 8.8
CVE-2025-34510EPSS 17%

Sitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10.0 through 10.4 are affected …

Fix: 10.4+
Fix from $1,950 2025-06-17
Experience Commerce HIGH 8.8
CVE-2025-34511EPSS 16%

Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an u…

Fix: 10.4+
Fix from $1,950 2025-06-17
Experience Commerce HIGH 7.5
CVE-2025-34509EPSS 55%

Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 0119…

Fix: 10.4+
Fix from $1,950 2025-06-17
Experience Commerce HIGH 7.5
CVE-2024-46938EPSS 46%

An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 …

Fix: after 10.4
Fix from $1,950 2024-09-15
Experience Commerce CRITICAL 9.8
CVE-2023-35813EPSS 87%

Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.

Fix: after 10.3
Fix from $2,300 2023-06-17
Experience Platform HIGH 8.8
CVE-2023-33652

Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /siteco…

No fix yet
Fix from $1,950 2023-06-06
Experience Platform HIGH 8.8
CVE-2023-33653

Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /Applic…

No fix yet
Fix from $1,950 2023-06-06
Experience Commerce HIGH 7.5
CVE-2023-33651

An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initial Release…

Fix: after 10.3
Fix from $1,950 2023-06-06
Experience Platform CRITICAL 9.8
CVE-2023-27068

Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationResult.asp…

Fix: 10.2+
Fix from $2,300 2023-05-23
Experience Platform HIGH 7.5
CVE-2023-27067

Directory Traversal vulnerability in Sitecore Experience Platform through 10.2 allows remote attackers to download arbitrary files via crafted comman…

Fix: after 10.2
Fix from $1,950 2023-05-22
Experience Platform MEDIUM 6.5
CVE-2023-27066

Directory Traversal vulnerability in Site Core Experience Platform 10.2 and earlier allows authenticated remote attackers to download arbitrary files…

Fix: after 10.2
Fix from $1,600 2023-05-22
Experience Manager HIGH 7.2
CVE-2023-26262

An issue was discovered in Sitecore XP/XM 10.3. As an authenticated Sitecore user, a unrestricted language file upload vulnerability exists the can l…

Fix: 10.3+
Fix from $1,950 2023-03-14
Experience Platform CRITICAL 9.8
CVE-2021-42237 KEVEPSS 98%

Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remot…

Mitigation only
Fix from $2,300 2021-11-05
Sitecore HIGH 8.8
CVE-2021-38366

Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve remote code execution b…

Fix: after 10.1
Fix from $1,950 2021-08-12
Cms MEDIUM 6.1
CVE-2019-11198

Multiple cross-site scripting (XSS) vulnerabilities in Sitecore CMS 9.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML v…

Fix: after 9.0.1
Fix from $1,600 2019-08-05
Experience Platform MEDIUM 5.4
CVE-2019-13493

In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user can modify the uploaded f…

No fix yet
Fix from $1,600 2019-07-17
Experience Platform HIGH 8.8
CVE-2019-11080EPSS 14%

Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. An authenticated user …

Fix: 9.1.1+
Fix from $1,950 2019-06-06
Cms CRITICAL 9.8
CVE-2019-9874 KEVEPSS 84%

Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allo…

Fix: after 8.2
Fix from $2,300 2019-05-31
Cms HIGH 8.8
CVE-2019-9875 KEVEPSS 14%

Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sendi…

Fix: after 9.1
Fix from $1,950 2019-05-31
Rocks CRITICAL 9.8
CVE-2019-12440

The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious commands and code via the Sitecore R…

Fix: 2.1.149+
Fix from $2,300 2019-05-29
Sitecore.net HIGH 7.5
CVE-2018-7669EPSS 17%

An issue was discovered in Sitecore Sitecore.NET 8.1 rev. 151207 Hotfix 141178-1 and above. The 'Log Viewer' application is vulnerable to a directory…

No fix yet
Fix from $1,950 2018-04-27
Cms MEDIUM 5.4
CVE-2017-11439

In Sitecore 8.2, there is reflected XSS in the shell/Applications/Tools/Run Program parameter.

No fix yet
Fix from $1,600 2017-07-19
Sitecore.net MEDIUM 6.1
CVE-2017-9356

Sitecore.NET 7.1 through 7.2 has a Cross Site Scripting Vulnerability via the searchStr parameter to the /Search-Results URI.

No fix yet
Fix from $1,600 2017-06-23
Crm MEDIUM 6.7
CVE-2017-5965

The package manager in Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to execute arbitrary ASP code by creating a ZIP archive…

No fix yet
Fix from $1,600 2017-05-23
Experience Platform MEDIUM 6.1
CVE-2016-8855

Cross-Site Scripting (XSS) in "/sitecore/client/Applications/List Manager/Taskpages/Contact list" in Sitecore Experience Platform 8.1 rev. 160519 (8.…

No fix yet
Fix from $1,600 2017-03-19
Staging Module MEDIUM 6.8
CVE-2009-4367EPSS 6%

The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote attackers …

Fix: after 5.4.0
Fix from $1,600 2009-12-21