Experience manager
This hub aggregates every CVE we track for Experience manager, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
18
CVEs tracked
5
Critical
11
High
1
In CISA KEV
Severity distribution
HIGH11CRITICAL5MEDIUM2
Monthly trend
1
0
0
0
0
0
0
0
0
3
0
0
4
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Experience manager.
- CVE-2025-53690Sitecore Products ViewState Deserialization VulnerabilityKEV9.0
- CVE-2025-53691Sitecore Experience Remote Code Execution through Insecure Deserialization8.8
- CVE-2025-53693HTML Cache Poisoning through Unsafe Reflections9.8
- CVE-2025-53694Information Disclosure in ItemServices API7.5
- CVE-2025-34511Sitecore PowerShell Extension RCE via Unrestricted Upload8.8
- CVE-2025-34510Sitecore XM, XC, and XP Post-Auth RCE via Zip Slip8.8
- CVE-2025-34509Sitecore XM and XP Hardcoded Credentials7.5
- CVE-2024-46938An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated attacker can...7.5
- CVE-2023-35813Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.9.8
- CVE-2023-33651An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initial Release to v13.0 Initial Release allows attackers to by...7.5
- CVE-2023-26262An issue was discovered in Sitecore XP/XM 10.3. As an authenticated Sitecore user, a unrestricted language file upload vulnerability exists the can lead to direct code execution on the content mana...7.2
- CVE-2020-14989An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows CSRF if the attacker uses GET where POST was intended.6.5
- CVE-2020-14988An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows XSS in the login page via the loginmessage parameter, the text editor via the src attribute of HTML e...5.4
- CVE-2020-14987An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows remote attackers to execute arbitrary code because there is a mishandling of the capability for admin...7.2
- CVE-2020-24445Cross-site Scripting Vulnerability in Commenting Function of Adobe Experience Manager (AEM)9.0
Product normalization is registry-driven with AI assist and human review. How it works