Optimizely records
12 published records for vendor optimizely.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-472 External Control of Assumed-Immutable Web Parameter1
- CWE-521 Weak Password Requirements1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-613 Insufficient Session Expiration1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2025-22389No exploit | An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0.optimizely · optimizely cms · CWE-434 | High8.0 | — | 0.5% | Jan 3, 2025 |
32Monitor | CVE-2024-56174No exploit | In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specioptimizely · configured commerce · CWE-79 | High8.1 | — | 0.4% | Dec 18, 2024 |
30Monitor | CVE-2025-22384No exploit | An issue was discovered in Optimizely Configured Commerce before 5.2.2408.optimizely · configured commerce · CWE-472 | High7.5 | — | 0.4% | Jan 3, 2025 |
30Monitor | CVE-2025-22387No exploit | An issue was discovered in Optimizely Configured Commerce before 5.2.2408.optimizely · configured commerce · CWE-598 | High7.5 | — | 0.4% | Jan 3, 2025 |
30Monitor | CVE-2025-22390No exploit | An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0.optimizely · optimizely cms · CWE-521 | High7.5 | — | 0.4% | Jan 3, 2025 |
29Monitor | CVE-2025-22386No exploit | An issue was discovered in Optimizely Configured Commerce before 5.2.2408.optimizely · configured commerce · CWE-613 | High7.3 | — | 0.3% | Jan 3, 2025 |
24Monitor | CVE-2024-56175No exploit | In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specioptimizely · configured commerce · CWE-79 | Medium6.1 | — | 0.2% | Dec 18, 2024 |
23Monitor | CVE-2025-22385No exploit | An issue was discovered in Optimizely Configured Commerce before 5.2.2408.optimizely · configured commerce · CWE-862 | Medium5.9 | — | 0.3% | Jan 3, 2025 |
22Monitor | CVE-2025-22388No exploit | An issue was discovered in Optimizely EPiServer.CMS.Core before 12.22.0.optimizely · optimizely cms · CWE-79 | Medium5.7 | — | 0.3% | Jan 3, 2025 |
19Monitor | CVE-2023-31754No exploit | Optimizely CMS UI before v12.16.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Admin panel.optimizely · optimizely cms · CWE-79 | Medium4.8 | — | 0.4% | Nov 14, 2023 |
18Monitor | CVE-2024-56173No exploit | In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specioptimizely · configured commerce · CWE-79 | Medium4.7 | — | 0.3% | Dec 18, 2024 |
18Monitor | CVE-2025-22383No exploit | An issue was discovered in Optimizely Configured Commerce before 5.2.2408.optimizely · configured commerce · CWE-79 | Medium4.6 | — | 0.2% | Jan 3, 2025 |
- CVE-2025-2238932Monitor
An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0.
HighCVSS 8.0No exploitEPSS 0%optimizely · optimizely cmsJan 3, 2025
- CVE-2024-5617432Monitor
In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under speci
HighCVSS 8.1No exploitEPSS 0%optimizely · configured commerceDec 18, 2024
- CVE-2025-2238430Monitor
An issue was discovered in Optimizely Configured Commerce before 5.2.2408.
HighCVSS 7.5No exploitEPSS 0%optimizely · configured commerceJan 3, 2025
- CVE-2025-2238730Monitor
An issue was discovered in Optimizely Configured Commerce before 5.2.2408.
HighCVSS 7.5No exploitEPSS 0%optimizely · configured commerceJan 3, 2025
- CVE-2025-2239030Monitor
An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0.
HighCVSS 7.5No exploitEPSS 0%optimizely · optimizely cmsJan 3, 2025
- CVE-2025-2238629Monitor
An issue was discovered in Optimizely Configured Commerce before 5.2.2408.
HighCVSS 7.3No exploitEPSS 0%optimizely · configured commerceJan 3, 2025
- CVE-2024-5617524Monitor
In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under speci
MediumCVSS 6.1No exploitEPSS 0%optimizely · configured commerceDec 18, 2024
- CVE-2025-2238523Monitor
An issue was discovered in Optimizely Configured Commerce before 5.2.2408.
MediumCVSS 5.9No exploitEPSS 0%optimizely · configured commerceJan 3, 2025
- CVE-2025-2238822Monitor
An issue was discovered in Optimizely EPiServer.CMS.Core before 12.22.0.
MediumCVSS 5.7No exploitEPSS 0%optimizely · optimizely cmsJan 3, 2025
- CVE-2023-3175419Monitor
Optimizely CMS UI before v12.16.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Admin panel.
MediumCVSS 4.8No exploitEPSS 0%optimizely · optimizely cmsNov 14, 2023
- CVE-2024-5617318Monitor
In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under speci
MediumCVSS 4.7No exploitEPSS 0%optimizely · configured commerceDec 18, 2024
- CVE-2025-2238318Monitor
An issue was discovered in Optimizely Configured Commerce before 5.2.2408.
MediumCVSS 4.6No exploitEPSS 0%optimizely · configured commerceJan 3, 2025