Записи Sitecore
35 опубликованных записей вендора sitecore.
Профиль для исследователя
- Попали в KEV
- 4 · 11,4 %
- С эксплойтом
- 6 · 17,1 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 2,9 %
- Медиана: публикация → KEV
- 1133 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-502 Deserialization of Untrusted Data7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-287 Improper Authentication2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
35 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
98Срочно | CVE-2021-42237Готовый эксплойт | Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achisitecore · experience platform · CWE-502 | Критическая9,8 | KEV | 97,6 % | 5 нояб. 2021 г. |
94Срочно | CVE-2019-9874Готовый эксплойт | Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 tositecore · cms · CWE-502 | Критическая9,8 | KEV | 83,7 % | 31 мая 2019 г. |
81Срочно | CVE-2025-53690Готовый эксплойт | Sitecore Products ViewState Deserialization Vulnerabilitysitecore · experience commerce · CWE-502 | Критическая9,0 | KEV | 51,1 % | 3 сент. 2025 г. |
69На этой неделе | CVE-2019-9875Готовый эксплойт | Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary codesitecore · cms · CWE-502 | Высокая8,8 | KEV | 13,8 % | 31 мая 2019 г. |
65На этой неделе | CVE-2023-35813Proof of concept | Multiple Sitecore products allow remote code execution.sitecore · experience commerce · CWE-94 | Критическая9,8 | — | 86,7 % | 17 июн. 2023 г. |
47В плане | CVE-2025-34509Proof of concept | Sitecore XM and XP Hardcoded Credentialssitecore · experience commerce · CWE-798 | Высокая7,5 | — | 55,9 % | 17 июн. 2025 г. |
45В плане | CVE-2025-53693Proof of concept | HTML Cache Poisoning through Unsafe Reflectionssitecore · experience commerce · CWE-470 | Критическая9,8 | — | 19,4 % | 3 сент. 2025 г. |
44В плане | CVE-2024-46938Proof of concept | An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release thrositecore · experience commerce · CWE-200 | Высокая7,5 | — | 46,8 % | 15 сент. 2024 г. |
44В плане | CVE-2025-34511Готовый эксплойт | Sitecore PowerShell Extension RCE via Unrestricted Uploadsitecore · experience commerce · CWE-434 | Высокая8,8 | — | 29,8 % | 17 июн. 2025 г. |
42В плане | CVE-2025-34510Готовый эксплойт | Sitecore XM, XC, and XP Post-Auth RCE via Zip Slipsitecore · experience commerce · CWE-23 | Высокая8,8 | — | 24,3 % | 17 июн. 2025 г. |
40В плане | CVE-2019-12440Эксплойта нет | The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious commands and code via the Ssitecore · rocks · CWE-287 | Критическая9,8 | — | 2,1 % | 29 мая 2019 г. |
40В плане | CVE-2023-27068Эксплойта нет | Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationRsitecore · experience platform · CWE-502 | Критическая9,8 | — | 1,7 % | 22 мая 2023 г. |
39Наблюдать | CVE-2019-11080Proof of concept | Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863.sitecore · experience platform · CWE-502 | Высокая8,8 | — | 13,9 % | 6 июн. 2019 г. |
36Наблюдать | CVE-2021-38366Эксплойта нет | Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve remote code exsitecore · sitecore · CWE-434 | Высокая8,8 | — | 2,9 % | 12 авг. 2021 г. |
36Наблюдать | CVE-2023-33652Эксплойта нет | Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the componensitecore · experience platform · CWE-470 | Высокая8,8 | — | 2,5 % | 6 июн. 2023 г. |
36Наблюдать | CVE-2023-33653Эксплойта нет | Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the componensitecore · experience platform | Высокая8,8 | — | 2,1 % | 6 июн. 2023 г. |
35Наблюдать | CVE-2018-7669Proof of concept | An issue was discovered in Sitecore Sitecore.NET 8.1 rev.sitecore · sitecore.net · CWE-22 | Высокая7,5 | — | 16,9 % | 27 апр. 2018 г. |
35Наблюдать | CVE-2025-53691Proof of concept | Sitecore Experience Remote Code Execution through Insecure Deserializationsitecore · experience commerce · CWE-502 | Высокая8,8 | — | 1,6 % | 3 сент. 2025 г. |
32Наблюдать | CVE-2025-53694Proof of concept | Information Disclosure in ItemServices APIsitecore · experience commerce · CWE-200 | Высокая7,5 | — | 6,5 % | 3 сент. 2025 г. |
30Наблюдать | CVE-2023-27067Эксплойта нет | Directory Traversal vulnerability in Sitecore Experience Platform through 10.2 allows remote attackers to download arbitrary files via craftsitecore · experience platform · CWE-22 | Высокая7,5 | — | 1,6 % | 22 мая 2023 г. |
30Наблюдать | CVE-2023-33651Эксплойта нет | An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initiasitecore · experience commerce · CWE-863 | Высокая7,5 | — | 1,4 % | 6 июн. 2023 г. |
29Наблюдать | CVE-2009-4367Proof of concept | The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote asitecore · staging module · CWE-287 | Средняя6,8 | — | 6,1 % | 21 дек. 2009 г. |
28Наблюдать | CVE-2023-26262Proof of concept | An issue was discovered in Sitecore XP/XM 10.3.sitecore · experience manager · CWE-434 | Высокая7,2 | — | 1,7 % | 14 мар. 2023 г. |
26Наблюдать | CVE-2023-27066Эксплойта нет | Directory Traversal vulnerability in Site Core Experience Platform 10.2 and earlier allows authenticated remote attackers to download arbitrsitecore · experience platform · CWE-22 | Средняя6,5 | — | 1,5 % | 22 мая 2023 г. |
26Наблюдать | CVE-2017-5965Эксплойта нет | The package manager in Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to execute arbitrary ASP code by creating a ZIsitecore · crm | Средняя6,7 | — | 1,0 % | 23 мая 2017 г. |
- CVE-2021-4223798Срочно
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achi
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %sitecore · experience platform5 нояб. 2021 г.
- CVE-2019-987494Срочно
Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 84 %sitecore · cms31 мая 2019 г.
- CVE-2025-5369081Срочно
Sitecore Products ViewState Deserialization Vulnerability
КритическаяCVSS 9,0KEVГотовый эксплойтEPSS 51 %sitecore · experience commerce3 сент. 2025 г.
- CVE-2019-987569На этой неделе
Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 14 %sitecore · cms31 мая 2019 г.
- CVE-2023-3581365На этой неделе
Multiple Sitecore products allow remote code execution.
КритическаяCVSS 9,8Proof of conceptEPSS 87 %sitecore · experience commerce17 июн. 2023 г.
- CVE-2025-3450947В плане
Sitecore XM and XP Hardcoded Credentials
ВысокаяCVSS 7,5Proof of conceptEPSS 56 %sitecore · experience commerce17 июн. 2025 г.
- CVE-2025-5369345В плане
HTML Cache Poisoning through Unsafe Reflections
КритическаяCVSS 9,8Proof of conceptEPSS 19 %sitecore · experience commerce3 сент. 2025 г.
- CVE-2024-4693844В плане
An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release thro
ВысокаяCVSS 7,5Proof of conceptEPSS 47 %sitecore · experience commerce15 сент. 2024 г.
- CVE-2025-3451144В плане
Sitecore PowerShell Extension RCE via Unrestricted Upload
ВысокаяCVSS 8,8Готовый эксплойтEPSS 30 %sitecore · experience commerce17 июн. 2025 г.
- CVE-2025-3451042В плане
Sitecore XM, XC, and XP Post-Auth RCE via Zip Slip
ВысокаяCVSS 8,8Готовый эксплойтEPSS 24 %sitecore · experience commerce17 июн. 2025 г.
- CVE-2019-1244040В плане
The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious commands and code via the S
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %sitecore · rocks29 мая 2019 г.
- CVE-2023-2706840В плане
Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationR
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %sitecore · experience platform22 мая 2023 г.
- CVE-2019-1108039Наблюдать
Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863.
ВысокаяCVSS 8,8Proof of conceptEPSS 14 %sitecore · experience platform6 июн. 2019 г.
- CVE-2021-3836636Наблюдать
Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve remote code ex
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %sitecore · sitecore12 авг. 2021 г.
- CVE-2023-3365236Наблюдать
Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the componen
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %sitecore · experience platform6 июн. 2023 г.
- CVE-2023-3365336Наблюдать
Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the componen
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %sitecore · experience platform6 июн. 2023 г.
- CVE-2018-766935Наблюдать
An issue was discovered in Sitecore Sitecore.NET 8.1 rev.
ВысокаяCVSS 7,5Proof of conceptEPSS 17 %sitecore · sitecore.net27 апр. 2018 г.
- CVE-2025-5369135Наблюдать
Sitecore Experience Remote Code Execution through Insecure Deserialization
ВысокаяCVSS 8,8Proof of conceptEPSS 2 %sitecore · experience commerce3 сент. 2025 г.
- CVE-2025-5369432Наблюдать
Information Disclosure in ItemServices API
ВысокаяCVSS 7,5Proof of conceptEPSS 6 %sitecore · experience commerce3 сент. 2025 г.
- CVE-2023-2706730Наблюдать
Directory Traversal vulnerability in Sitecore Experience Platform through 10.2 allows remote attackers to download arbitrary files via craft
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %sitecore · experience platform22 мая 2023 г.
- CVE-2023-3365130Наблюдать
An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initia
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %sitecore · experience commerce6 июн. 2023 г.
- CVE-2009-436729Наблюдать
The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote a
СредняяCVSS 6,8Proof of conceptEPSS 6 %sitecore · staging module21 дек. 2009 г.
- CVE-2023-2626228Наблюдать
An issue was discovered in Sitecore XP/XM 10.3.
ВысокаяCVSS 7,2Proof of conceptEPSS 2 %sitecore · experience manager14 мар. 2023 г.
- CVE-2023-2706626Наблюдать
Directory Traversal vulnerability in Site Core Experience Platform 10.2 and earlier allows authenticated remote attackers to download arbitr
СредняяCVSS 6,5Эксплойта нетEPSS 1 %sitecore · experience platform22 мая 2023 г.
- CVE-2017-596526Наблюдать
The package manager in Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to execute arbitrary ASP code by creating a ZI
СредняяCVSS 6,7Эксплойта нетEPSS 1 %sitecore · crm23 мая 2017 г.