Experience commerce
This hub aggregates every CVE we track for Experience commerce, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
10
CVEs tracked
3
Critical
7
High
1
In CISA KEV
Severity distribution
HIGH7CRITICAL3
Monthly trend
1
0
0
0
0
0
0
0
0
3
0
0
4
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 10 most recently published vulnerabilities affecting Experience commerce.
- CVE-2025-53690Sitecore Products ViewState Deserialization VulnerabilityKEV9.0
- CVE-2025-53691Sitecore Experience Remote Code Execution through Insecure Deserialization8.8
- CVE-2025-53693HTML Cache Poisoning through Unsafe Reflections9.8
- CVE-2025-53694Information Disclosure in ItemServices API7.5
- CVE-2025-34511Sitecore PowerShell Extension RCE via Unrestricted Upload8.8
- CVE-2025-34510Sitecore XM, XC, and XP Post-Auth RCE via Zip Slip8.8
- CVE-2025-34509Sitecore XM and XP Hardcoded Credentials7.5
- CVE-2024-46938An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated attacker can...7.5
- CVE-2023-35813Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.9.8
- CVE-2023-33651An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initial Release to v13.0 Initial Release allows attackers to by...7.5
Product normalization is registry-driven with AI assist and human review. How it works