Sitecore records
35 published records for vendor sitecore.
Researcher profile
- Entered KEV
- 4 · 11.4%
- Weaponized
- 6 · 17.1%
- Pre-auth RCE
- 5
- With a fix record
- 2.9%
- Median publish → KEV
- 1133 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-502 Deserialization of Untrusted Data7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-287 Improper Authentication2
The weakness classes this vendor ships most often: where to look.
CWEAll records
35 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
98Now | CVE-2021-42237Weaponized | Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achisitecore · experience platform · CWE-502 | Critical9.8 | KEV | 97.6% | Nov 5, 2021 |
94Now | CVE-2019-9874Weaponized | Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 tositecore · cms · CWE-502 | Critical9.8 | KEV | 83.7% | May 31, 2019 |
81Now | CVE-2025-53690Weaponized | Sitecore Products ViewState Deserialization Vulnerabilitysitecore · experience commerce · CWE-502 | Critical9.0 | KEV | 51.1% | Sep 3, 2025 |
69This week | CVE-2019-9875Weaponized | Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary codesitecore · cms · CWE-502 | High8.8 | KEV | 13.8% | May 31, 2019 |
65This week | CVE-2023-35813Proof of concept | Multiple Sitecore products allow remote code execution.sitecore · experience commerce · CWE-94 | Critical9.8 | — | 86.7% | Jun 17, 2023 |
47Plan | CVE-2025-34509Proof of concept | Sitecore XM and XP Hardcoded Credentialssitecore · experience commerce · CWE-798 | High7.5 | — | 55.9% | Jun 17, 2025 |
44Plan | CVE-2024-46938Proof of concept | An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release thrositecore · experience commerce · CWE-200 | High7.5 | — | 46.8% | Sep 15, 2024 |
44Plan | CVE-2025-34511Weaponized | Sitecore PowerShell Extension RCE via Unrestricted Uploadsitecore · experience commerce · CWE-434 | High8.8 | — | 29.8% | Jun 17, 2025 |
43Plan | CVE-2025-53693Proof of concept | HTML Cache Poisoning through Unsafe Reflectionssitecore · experience commerce · CWE-470 | Critical9.8 | — | 14.8% | Sep 3, 2025 |
42Plan | CVE-2025-34510Weaponized | Sitecore XM, XC, and XP Post-Auth RCE via Zip Slipsitecore · experience commerce · CWE-23 | High8.8 | — | 24.3% | Jun 17, 2025 |
40Plan | CVE-2019-12440No exploit | The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious commands and code via the Ssitecore · rocks · CWE-287 | Critical9.8 | — | 2.1% | May 29, 2019 |
40Plan | CVE-2023-27068No exploit | Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationRsitecore · experience platform · CWE-502 | Critical9.8 | — | 1.7% | May 22, 2023 |
39Monitor | CVE-2019-11080Proof of concept | Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863.sitecore · experience platform · CWE-502 | High8.8 | — | 13.9% | Jun 6, 2019 |
36Monitor | CVE-2021-38366No exploit | Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve remote code exsitecore · sitecore · CWE-434 | High8.8 | — | 2.9% | Aug 12, 2021 |
36Monitor | CVE-2023-33652No exploit | Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the componensitecore · experience platform · CWE-470 | High8.8 | — | 2.5% | Jun 6, 2023 |
36Monitor | CVE-2023-33653No exploit | Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the componensitecore · experience platform | High8.8 | — | 2.1% | Jun 6, 2023 |
35Monitor | CVE-2018-7669Proof of concept | An issue was discovered in Sitecore Sitecore.NET 8.1 rev.sitecore · sitecore.net · CWE-22 | High7.5 | — | 17.2% | Apr 27, 2018 |
35Monitor | CVE-2025-53691Proof of concept | Sitecore Experience Remote Code Execution through Insecure Deserializationsitecore · experience commerce · CWE-502 | High8.8 | — | 1.6% | Sep 3, 2025 |
32Monitor | CVE-2025-53694Proof of concept | Information Disclosure in ItemServices APIsitecore · experience commerce · CWE-200 | High7.5 | — | 6.0% | Sep 3, 2025 |
30Monitor | CVE-2023-27067No exploit | Directory Traversal vulnerability in Sitecore Experience Platform through 10.2 allows remote attackers to download arbitrary files via craftsitecore · experience platform · CWE-22 | High7.5 | — | 1.6% | May 22, 2023 |
30Monitor | CVE-2023-33651No exploit | An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initiasitecore · experience commerce · CWE-863 | High7.5 | — | 1.4% | Jun 6, 2023 |
29Monitor | CVE-2009-4367Proof of concept | The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote asitecore · staging module · CWE-287 | Medium6.8 | — | 6.1% | Dec 21, 2009 |
28Monitor | CVE-2023-26262Proof of concept | An issue was discovered in Sitecore XP/XM 10.3.sitecore · experience manager · CWE-434 | High7.2 | — | 1.7% | Mar 14, 2023 |
26Monitor | CVE-2023-27066No exploit | Directory Traversal vulnerability in Site Core Experience Platform 10.2 and earlier allows authenticated remote attackers to download arbitrsitecore · experience platform · CWE-22 | Medium6.5 | — | 1.5% | May 22, 2023 |
26Monitor | CVE-2017-5965No exploit | The package manager in Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to execute arbitrary ASP code by creating a ZIsitecore · crm | Medium6.7 | — | 1.0% | May 23, 2017 |
- CVE-2021-4223798Now
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achi
CriticalCVSS 9.8KEVWeaponizedEPSS 98%sitecore · experience platformNov 5, 2021
- CVE-2019-987494Now
Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to
CriticalCVSS 9.8KEVWeaponizedEPSS 84%sitecore · cmsMay 31, 2019
- CVE-2025-5369081Now
Sitecore Products ViewState Deserialization Vulnerability
CriticalCVSS 9.0KEVWeaponizedEPSS 51%sitecore · experience commerceSep 3, 2025
- CVE-2019-987569This week
Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code
HighCVSS 8.8KEVWeaponizedEPSS 14%sitecore · cmsMay 31, 2019
- CVE-2023-3581365This week
Multiple Sitecore products allow remote code execution.
CriticalCVSS 9.8Proof of conceptEPSS 87%sitecore · experience commerceJun 17, 2023
- CVE-2025-3450947Plan
Sitecore XM and XP Hardcoded Credentials
HighCVSS 7.5Proof of conceptEPSS 56%sitecore · experience commerceJun 17, 2025
- CVE-2024-4693844Plan
An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release thro
HighCVSS 7.5Proof of conceptEPSS 47%sitecore · experience commerceSep 15, 2024
- CVE-2025-3451144Plan
Sitecore PowerShell Extension RCE via Unrestricted Upload
HighCVSS 8.8WeaponizedEPSS 30%sitecore · experience commerceJun 17, 2025
- CVE-2025-5369343Plan
HTML Cache Poisoning through Unsafe Reflections
CriticalCVSS 9.8Proof of conceptEPSS 15%sitecore · experience commerceSep 3, 2025
- CVE-2025-3451042Plan
Sitecore XM, XC, and XP Post-Auth RCE via Zip Slip
HighCVSS 8.8WeaponizedEPSS 24%sitecore · experience commerceJun 17, 2025
- CVE-2019-1244040Plan
The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious commands and code via the S
CriticalCVSS 9.8No exploitEPSS 2%sitecore · rocksMay 29, 2019
- CVE-2023-2706840Plan
Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationR
CriticalCVSS 9.8No exploitEPSS 2%sitecore · experience platformMay 22, 2023
- CVE-2019-1108039Monitor
Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863.
HighCVSS 8.8Proof of conceptEPSS 14%sitecore · experience platformJun 6, 2019
- CVE-2021-3836636Monitor
Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve remote code ex
HighCVSS 8.8No exploitEPSS 3%sitecore · sitecoreAug 12, 2021
- CVE-2023-3365236Monitor
Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the componen
HighCVSS 8.8No exploitEPSS 2%sitecore · experience platformJun 6, 2023
- CVE-2023-3365336Monitor
Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the componen
HighCVSS 8.8No exploitEPSS 2%sitecore · experience platformJun 6, 2023
- CVE-2018-766935Monitor
An issue was discovered in Sitecore Sitecore.NET 8.1 rev.
HighCVSS 7.5Proof of conceptEPSS 17%sitecore · sitecore.netApr 27, 2018
- CVE-2025-5369135Monitor
Sitecore Experience Remote Code Execution through Insecure Deserialization
HighCVSS 8.8Proof of conceptEPSS 2%sitecore · experience commerceSep 3, 2025
- CVE-2025-5369432Monitor
Information Disclosure in ItemServices API
HighCVSS 7.5Proof of conceptEPSS 6%sitecore · experience commerceSep 3, 2025
- CVE-2023-2706730Monitor
Directory Traversal vulnerability in Sitecore Experience Platform through 10.2 allows remote attackers to download arbitrary files via craft
HighCVSS 7.5No exploitEPSS 2%sitecore · experience platformMay 22, 2023
- CVE-2023-3365130Monitor
An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initia
HighCVSS 7.5No exploitEPSS 1%sitecore · experience commerceJun 6, 2023
- CVE-2009-436729Monitor
The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote a
MediumCVSS 6.8Proof of conceptEPSS 6%sitecore · staging moduleDec 21, 2009
- CVE-2023-2626228Monitor
An issue was discovered in Sitecore XP/XM 10.3.
HighCVSS 7.2Proof of conceptEPSS 2%sitecore · experience managerMar 14, 2023
- CVE-2023-2706626Monitor
Directory Traversal vulnerability in Site Core Experience Platform 10.2 and earlier allows authenticated remote attackers to download arbitr
MediumCVSS 6.5No exploitEPSS 1%sitecore · experience platformMay 22, 2023
- CVE-2017-596526Monitor
The package manager in Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to execute arbitrary ASP code by creating a ZI
MediumCVSS 6.7No exploitEPSS 1%sitecore · crmMay 23, 2017