İçeriğe atla
Noroxi

Sitecore kayıtları

sitecore üreticisine ait 35 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
4 · %11,4
Silahlaştırılmış
6 · %17,1
Pre-auth RCE
5
Düzeltme kaydı olan
%2,9
Yayından KEV’e ortanca
1133 gün

Tüm kayıtlar

35 kayıt
  • Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achi

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %98

    sitecore · experience platform5 Kas 2021

  • Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %84

    sitecore · cms31 May 2019

  • Sitecore Products ViewState Deserialization Vulnerability

    KritikCVSS 9,0KEVSilahlaştırılmışEPSS %51

    sitecore · experience commerce3 Eyl 2025

  • CVE-2019-9875
    69Bu hafta

    Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %14

    sitecore · cms31 May 2019

  • CVE-2023-35813
    65Bu hafta

    Multiple Sitecore products allow remote code execution.

    KritikCVSS 9,8Kavram kanıtıEPSS %87

    sitecore · experience commerce17 Haz 2023

  • CVE-2025-34509
    47Planlayın

    Sitecore XM and XP Hardcoded Credentials

    YüksekCVSS 7,5Kavram kanıtıEPSS %56

    sitecore · experience commerce17 Haz 2025

  • CVE-2024-46938
    44Planlayın

    An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release thro

    YüksekCVSS 7,5Kavram kanıtıEPSS %47

    sitecore · experience commerce15 Eyl 2024

  • CVE-2025-34511
    44Planlayın

    Sitecore PowerShell Extension RCE via Unrestricted Upload

    YüksekCVSS 8,8SilahlaştırılmışEPSS %30

    sitecore · experience commerce17 Haz 2025

  • CVE-2025-53693
    43Planlayın

    HTML Cache Poisoning through Unsafe Reflections

    KritikCVSS 9,8Kavram kanıtıEPSS %15

    sitecore · experience commerce3 Eyl 2025

  • CVE-2025-34510
    42Planlayın

    Sitecore XM, XC, and XP Post-Auth RCE via Zip Slip

    YüksekCVSS 8,8SilahlaştırılmışEPSS %24

    sitecore · experience commerce17 Haz 2025

  • CVE-2019-12440
    40Planlayın

    The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious commands and code via the S

    KritikCVSS 9,8İstismar yokEPSS %2

    sitecore · rocks29 May 2019

  • CVE-2023-27068
    40Planlayın

    Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationR

    KritikCVSS 9,8İstismar yokEPSS %2

    sitecore · experience platform22 May 2023

  • CVE-2019-11080
    39İzleyin

    Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863.

    YüksekCVSS 8,8Kavram kanıtıEPSS %14

    sitecore · experience platform6 Haz 2019

  • CVE-2021-38366
    36İzleyin

    Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve remote code ex

    YüksekCVSS 8,8İstismar yokEPSS %3

    sitecore · sitecore12 Ağu 2021

  • CVE-2023-33652
    36İzleyin

    Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the componen

    YüksekCVSS 8,8İstismar yokEPSS %2

    sitecore · experience platform6 Haz 2023

  • CVE-2023-33653
    36İzleyin

    Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the componen

    YüksekCVSS 8,8İstismar yokEPSS %2

    sitecore · experience platform6 Haz 2023

  • CVE-2018-7669
    35İzleyin

    An issue was discovered in Sitecore Sitecore.NET 8.1 rev.

    YüksekCVSS 7,5Kavram kanıtıEPSS %17

    sitecore · sitecore.net27 Nis 2018

  • CVE-2025-53691
    35İzleyin

    Sitecore Experience Remote Code Execution through Insecure Deserialization

    YüksekCVSS 8,8Kavram kanıtıEPSS %2

    sitecore · experience commerce3 Eyl 2025

  • CVE-2025-53694
    32İzleyin

    Information Disclosure in ItemServices API

    YüksekCVSS 7,5Kavram kanıtıEPSS %6

    sitecore · experience commerce3 Eyl 2025

  • CVE-2023-27067
    30İzleyin

    Directory Traversal vulnerability in Sitecore Experience Platform through 10.2 allows remote attackers to download arbitrary files via craft

    YüksekCVSS 7,5İstismar yokEPSS %2

    sitecore · experience platform22 May 2023

  • CVE-2023-33651
    30İzleyin

    An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initia

    YüksekCVSS 7,5İstismar yokEPSS %1

    sitecore · experience commerce6 Haz 2023

  • CVE-2009-4367
    29İzleyin

    The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote a

    OrtaCVSS 6,8Kavram kanıtıEPSS %6

    sitecore · staging module21 Ara 2009

  • CVE-2023-26262
    28İzleyin

    An issue was discovered in Sitecore XP/XM 10.3.

    YüksekCVSS 7,2Kavram kanıtıEPSS %2

    sitecore · experience manager14 Mar 2023

  • CVE-2023-27066
    26İzleyin

    Directory Traversal vulnerability in Site Core Experience Platform 10.2 and earlier allows authenticated remote attackers to download arbitr

    OrtaCVSS 6,5İstismar yokEPSS %1

    sitecore · experience platform22 May 2023

  • CVE-2017-5965
    26İzleyin

    The package manager in Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to execute arbitrary ASP code by creating a ZI

    OrtaCVSS 6,7İstismar yokEPSS %1

    sitecore · crm23 May 2017