Sitecore experience manager
This hub aggregates every CVE we track for Sitecore experience manager, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
4
CVEs tracked
1
Critical
2
High
1
In CISA KEV
Severity distribution
HIGH2MEDIUM1CRITICAL1
Monthly trend
0
0
0
0
0
1
0
0
0
2
0
0
1
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 4 most recently published vulnerabilities affecting Sitecore experience manager.
- CVE-2025-53690Sitecore Products ViewState Deserialization VulnerabilityKEV9.0
- CVE-2025-34510Sitecore XM, XC, and XP Post-Auth RCE via Zip Slip8.8
- CVE-2025-34509Sitecore XM and XP Hardcoded Credentials7.5
- CVE-2025-27218Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through insecure deserialization.5.3
Product normalization is registry-driven with AI assist and human review. How it works