Sitecore experience platform
This hub aggregates every CVE we track for Sitecore experience platform, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
5
CVEs tracked
2
Critical
2
High
2
In CISA KEV
Severity distribution
HIGH2CRITICAL2MEDIUM1
Monthly trend
0
0
0
0
0
1
0
0
0
2
0
0
1
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 5 most recently published vulnerabilities affecting Sitecore experience platform.
- CVE-2025-53690Sitecore Products ViewState Deserialization VulnerabilityKEV9.0
- CVE-2025-34510Sitecore XM, XC, and XP Post-Auth RCE via Zip Slip8.8
- CVE-2025-34509Sitecore XM and XP Hardcoded Credentials7.5
- CVE-2025-27218Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through insecure deserialization.5.3
- CVE-2021-42237Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentic...KEV9.8
Product normalization is registry-driven with AI assist and human review. How it works