Sitecore kayıtları
sitecore üreticisine ait 35 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 4 · %11,4
- Silahlaştırılmış
- 6 · %17,1
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %2,9
- Yayından KEV’e ortanca
- 1133 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-502 Deserialization of Untrusted Data7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-287 Improper Authentication2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
35 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
98Hemen | CVE-2021-42237Silahlaştırılmış | Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achisitecore · experience platform · CWE-502 | Kritik9,8 | KEV | %97,6 | 5 Kas 2021 |
94Hemen | CVE-2019-9874Silahlaştırılmış | Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 tositecore · cms · CWE-502 | Kritik9,8 | KEV | %83,7 | 31 May 2019 |
81Hemen | CVE-2025-53690Silahlaştırılmış | Sitecore Products ViewState Deserialization Vulnerabilitysitecore · experience commerce · CWE-502 | Kritik9,0 | KEV | %51,1 | 3 Eyl 2025 |
69Bu hafta | CVE-2019-9875Silahlaştırılmış | Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary codesitecore · cms · CWE-502 | Yüksek8,8 | KEV | %13,8 | 31 May 2019 |
65Bu hafta | CVE-2023-35813Kavram kanıtı | Multiple Sitecore products allow remote code execution.sitecore · experience commerce · CWE-94 | Kritik9,8 | — | %86,7 | 17 Haz 2023 |
47Planlayın | CVE-2025-34509Kavram kanıtı | Sitecore XM and XP Hardcoded Credentialssitecore · experience commerce · CWE-798 | Yüksek7,5 | — | %55,9 | 17 Haz 2025 |
44Planlayın | CVE-2024-46938Kavram kanıtı | An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release thrositecore · experience commerce · CWE-200 | Yüksek7,5 | — | %46,8 | 15 Eyl 2024 |
44Planlayın | CVE-2025-34511Silahlaştırılmış | Sitecore PowerShell Extension RCE via Unrestricted Uploadsitecore · experience commerce · CWE-434 | Yüksek8,8 | — | %29,8 | 17 Haz 2025 |
43Planlayın | CVE-2025-53693Kavram kanıtı | HTML Cache Poisoning through Unsafe Reflectionssitecore · experience commerce · CWE-470 | Kritik9,8 | — | %14,8 | 3 Eyl 2025 |
42Planlayın | CVE-2025-34510Silahlaştırılmış | Sitecore XM, XC, and XP Post-Auth RCE via Zip Slipsitecore · experience commerce · CWE-23 | Yüksek8,8 | — | %24,3 | 17 Haz 2025 |
40Planlayın | CVE-2019-12440İstismar yok | The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious commands and code via the Ssitecore · rocks · CWE-287 | Kritik9,8 | — | %2,1 | 29 May 2019 |
40Planlayın | CVE-2023-27068İstismar yok | Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationRsitecore · experience platform · CWE-502 | Kritik9,8 | — | %1,7 | 22 May 2023 |
39İzleyin | CVE-2019-11080Kavram kanıtı | Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863.sitecore · experience platform · CWE-502 | Yüksek8,8 | — | %13,9 | 6 Haz 2019 |
36İzleyin | CVE-2021-38366İstismar yok | Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve remote code exsitecore · sitecore · CWE-434 | Yüksek8,8 | — | %2,9 | 12 Ağu 2021 |
36İzleyin | CVE-2023-33652İstismar yok | Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the componensitecore · experience platform · CWE-470 | Yüksek8,8 | — | %2,5 | 6 Haz 2023 |
36İzleyin | CVE-2023-33653İstismar yok | Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the componensitecore · experience platform | Yüksek8,8 | — | %2,1 | 6 Haz 2023 |
35İzleyin | CVE-2018-7669Kavram kanıtı | An issue was discovered in Sitecore Sitecore.NET 8.1 rev.sitecore · sitecore.net · CWE-22 | Yüksek7,5 | — | %17,2 | 27 Nis 2018 |
35İzleyin | CVE-2025-53691Kavram kanıtı | Sitecore Experience Remote Code Execution through Insecure Deserializationsitecore · experience commerce · CWE-502 | Yüksek8,8 | — | %1,6 | 3 Eyl 2025 |
32İzleyin | CVE-2025-53694Kavram kanıtı | Information Disclosure in ItemServices APIsitecore · experience commerce · CWE-200 | Yüksek7,5 | — | %6,0 | 3 Eyl 2025 |
30İzleyin | CVE-2023-27067İstismar yok | Directory Traversal vulnerability in Sitecore Experience Platform through 10.2 allows remote attackers to download arbitrary files via craftsitecore · experience platform · CWE-22 | Yüksek7,5 | — | %1,6 | 22 May 2023 |
30İzleyin | CVE-2023-33651İstismar yok | An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initiasitecore · experience commerce · CWE-863 | Yüksek7,5 | — | %1,4 | 6 Haz 2023 |
29İzleyin | CVE-2009-4367Kavram kanıtı | The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote asitecore · staging module · CWE-287 | Orta6,8 | — | %6,1 | 21 Ara 2009 |
28İzleyin | CVE-2023-26262Kavram kanıtı | An issue was discovered in Sitecore XP/XM 10.3.sitecore · experience manager · CWE-434 | Yüksek7,2 | — | %1,7 | 14 Mar 2023 |
26İzleyin | CVE-2023-27066İstismar yok | Directory Traversal vulnerability in Site Core Experience Platform 10.2 and earlier allows authenticated remote attackers to download arbitrsitecore · experience platform · CWE-22 | Orta6,5 | — | %1,5 | 22 May 2023 |
26İzleyin | CVE-2017-5965İstismar yok | The package manager in Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to execute arbitrary ASP code by creating a ZIsitecore · crm | Orta6,7 | — | %1,0 | 23 May 2017 |
- CVE-2021-4223798Hemen
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achi
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %98sitecore · experience platform5 Kas 2021
- CVE-2019-987494Hemen
Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %84sitecore · cms31 May 2019
- CVE-2025-5369081Hemen
Sitecore Products ViewState Deserialization Vulnerability
KritikCVSS 9,0KEVSilahlaştırılmışEPSS %51sitecore · experience commerce3 Eyl 2025
- CVE-2019-987569Bu hafta
Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %14sitecore · cms31 May 2019
- CVE-2023-3581365Bu hafta
Multiple Sitecore products allow remote code execution.
KritikCVSS 9,8Kavram kanıtıEPSS %87sitecore · experience commerce17 Haz 2023
- CVE-2025-3450947Planlayın
Sitecore XM and XP Hardcoded Credentials
YüksekCVSS 7,5Kavram kanıtıEPSS %56sitecore · experience commerce17 Haz 2025
- CVE-2024-4693844Planlayın
An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release thro
YüksekCVSS 7,5Kavram kanıtıEPSS %47sitecore · experience commerce15 Eyl 2024
- CVE-2025-3451144Planlayın
Sitecore PowerShell Extension RCE via Unrestricted Upload
YüksekCVSS 8,8SilahlaştırılmışEPSS %30sitecore · experience commerce17 Haz 2025
- CVE-2025-5369343Planlayın
HTML Cache Poisoning through Unsafe Reflections
KritikCVSS 9,8Kavram kanıtıEPSS %15sitecore · experience commerce3 Eyl 2025
- CVE-2025-3451042Planlayın
Sitecore XM, XC, and XP Post-Auth RCE via Zip Slip
YüksekCVSS 8,8SilahlaştırılmışEPSS %24sitecore · experience commerce17 Haz 2025
- CVE-2019-1244040Planlayın
The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious commands and code via the S
KritikCVSS 9,8İstismar yokEPSS %2sitecore · rocks29 May 2019
- CVE-2023-2706840Planlayın
Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationR
KritikCVSS 9,8İstismar yokEPSS %2sitecore · experience platform22 May 2023
- CVE-2019-1108039İzleyin
Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863.
YüksekCVSS 8,8Kavram kanıtıEPSS %14sitecore · experience platform6 Haz 2019
- CVE-2021-3836636İzleyin
Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve remote code ex
YüksekCVSS 8,8İstismar yokEPSS %3sitecore · sitecore12 Ağu 2021
- CVE-2023-3365236İzleyin
Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the componen
YüksekCVSS 8,8İstismar yokEPSS %2sitecore · experience platform6 Haz 2023
- CVE-2023-3365336İzleyin
Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the componen
YüksekCVSS 8,8İstismar yokEPSS %2sitecore · experience platform6 Haz 2023
- CVE-2018-766935İzleyin
An issue was discovered in Sitecore Sitecore.NET 8.1 rev.
YüksekCVSS 7,5Kavram kanıtıEPSS %17sitecore · sitecore.net27 Nis 2018
- CVE-2025-5369135İzleyin
Sitecore Experience Remote Code Execution through Insecure Deserialization
YüksekCVSS 8,8Kavram kanıtıEPSS %2sitecore · experience commerce3 Eyl 2025
- CVE-2025-5369432İzleyin
Information Disclosure in ItemServices API
YüksekCVSS 7,5Kavram kanıtıEPSS %6sitecore · experience commerce3 Eyl 2025
- CVE-2023-2706730İzleyin
Directory Traversal vulnerability in Sitecore Experience Platform through 10.2 allows remote attackers to download arbitrary files via craft
YüksekCVSS 7,5İstismar yokEPSS %2sitecore · experience platform22 May 2023
- CVE-2023-3365130İzleyin
An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initia
YüksekCVSS 7,5İstismar yokEPSS %1sitecore · experience commerce6 Haz 2023
- CVE-2009-436729İzleyin
The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote a
OrtaCVSS 6,8Kavram kanıtıEPSS %6sitecore · staging module21 Ara 2009
- CVE-2023-2626228İzleyin
An issue was discovered in Sitecore XP/XM 10.3.
YüksekCVSS 7,2Kavram kanıtıEPSS %2sitecore · experience manager14 Mar 2023
- CVE-2023-2706626İzleyin
Directory Traversal vulnerability in Site Core Experience Platform 10.2 and earlier allows authenticated remote attackers to download arbitr
OrtaCVSS 6,5İstismar yokEPSS %1sitecore · experience platform22 May 2023
- CVE-2017-596526İzleyin
The package manager in Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to execute arbitrary ASP code by creating a ZI
OrtaCVSS 6,7İstismar yokEPSS %1sitecore · crm23 May 2017