Optimizely's vulnerability footprint is concentrated in its e-commerce and content-management platform products, including Configured Commerce and Optimizely CMS, which sit in the request path of customer-facing web applications. The recurring exposure centers on input-handling and session-management weaknesses, including cross-site scripting, insufficient session expiration, missing authorization checks, and external control of web parameters, which are characteristic of web application platforms that process user input and manage user state. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Optimizely over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-56174HIGH In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from client-side tem | Dec 18, 2024 | 8.1 | 23 | NO | NO |
CVE-2025-22389HIGH An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS, where the application does not properly validate uploade | Jan 4, 2025 | 8.0 | 22 | NO | NO |
CVE-2025-22390HIGH An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS due to insufficient enforcement of password complexity re | Jan 4, 2025 | 7.5 | 21 | NO | NO |
CVE-2025-22387HIGH An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue exists in requests for resources where the session token is submitted as a URL pa | Jan 4, 2025 | 7.5 | 21 | NO | NO |
CVE-2025-22386HIGH An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity session issue exists in the Commerce B2B application, affecting the longevity of active | Jan 4, 2025 | 7.3 | 21 | NO | NO |
CVE-2025-22384HIGH An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue concerning business logic exists in the Commerce B2B application, which allows st | Jan 4, 2025 | 7.5 | 21 | NO | NO |
CVE-2025-22388MEDIUM An issue was discovered in Optimizely EPiServer.CMS.Core before 12.22.0. A high-severity Stored Cross-Site Scripting (XSS) vulnerability exists in the CMS, allowing malicious actor | Jan 4, 2025 | 5.7 | 18 | NO | NO |
CVE-2025-22385MEDIUM An issue was discovered in Optimizely Configured Commerce before 5.2.2408. For newly created accounts, the Commerce B2B application does not require email confirmation. This medium | Jan 4, 2025 | 5.9 | 18 | NO | NO |
CVE-2024-56175MEDIUM In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from client-side tem | Dec 18, 2024 | 6.1 | 18 | NO | NO |
CVE-2025-22383MEDIUM An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity input validation issue exists in the Commerce B2B application, affecting the Contact Us | Jan 4, 2025 | 4.6 | 16 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Optimizely.
Media articles that mention a CVE ID that affects a product developed by Optimizely — matched by CVE ID, not by vendor name.