CVE-2025-34510
- EPSS 87.27%
- Veröffentlicht 17.06.2025 18:46:04
- Zuletzt bearbeitet 08.09.2025 19:22:24
Sitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10.0 through 10.4 are affected by a Zip Slip vulnerability. A remote, authenticated attacker can exploit this issue by sending a cra...
CVE-2025-34509
- EPSS 23.18%
- Veröffentlicht 17.06.2025 18:20:57
- Zuletzt bearbeitet 27.12.2025 17:15:47
Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 011967 PRE, and 10.4 to 10.4.1 rev. 011941 PRE contain a hardcoded user account. Unauthenticated and remo...
CVE-2025-27218
- EPSS 57.65%
- Veröffentlicht 20.02.2025 05:15:15
- Zuletzt bearbeitet 20.02.2025 21:15:26
Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through insecure deserialization.
CVE-2024-46938
- EPSS 93.43%
- Veröffentlicht 15.09.2024 22:15:09
- Zuletzt bearbeitet 20.09.2024 18:15:10
An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated attacker can read arbitrary files.
CVE-2023-35813
- EPSS 93.52%
- Veröffentlicht 17.06.2023 23:15:09
- Zuletzt bearbeitet 17.12.2024 17:15:08
Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.
CVE-2023-33653
- EPSS 2.72%
- Veröffentlicht 06.06.2023 19:15:12
- Zuletzt bearbeitet 08.01.2025 16:15:30
Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /Applications/Content%20Manager/Execute.aspx?cmd=convert&mode=HTML.
CVE-2023-33652
- EPSS 3.66%
- Veröffentlicht 06.06.2023 19:15:12
- Zuletzt bearbeitet 08.01.2025 15:15:13
Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /sitecore/shell/Invoke.aspx.
CVE-2023-33651
- EPSS 0.43%
- Veröffentlicht 06.06.2023 19:15:12
- Zuletzt bearbeitet 08.01.2025 17:15:12
An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initial Release to v13.0 Initial Release allows attackers to bypass authorization rules.
CVE-2023-27068
- EPSS 1.89%
- Veröffentlicht 23.05.2023 01:15:09
- Zuletzt bearbeitet 28.01.2025 21:15:13
Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationResult.aspx.
CVE-2023-27067
- EPSS 0.79%
- Veröffentlicht 22.05.2023 19:15:09
- Zuletzt bearbeitet 31.01.2025 14:15:29
Directory Traversal vulnerability in Sitecore Experience Platform through 10.2 allows remote attackers to download arbitrary files via crafted command to download.aspx