Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Optimizely

First CVE: Nov 14, 2023Active for: 3 yearsTotal CVEs: 12
23.3
VTI Score
Low

Optimizely's vulnerability footprint is concentrated in its e-commerce and content-management platform products, including Configured Commerce and Optimizely CMS, which sit in the request path of customer-facing web applications. The recurring exposure centers on input-handling and session-management weaknesses, including cross-site scripting, insufficient session expiration, missing authorization checks, and external control of web parameters, which are characteristic of web application platforms that process user input and manage user state. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 40% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Optimizely over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 14, 2023
2 years ago
Most Recent CVE
Jan 4, 2025
566 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-56174HIGH
In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from client-side tem
Dec 18, 20248.123NONO
CVE-2025-22389HIGH
An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS, where the application does not properly validate uploade
Jan 4, 20258.022NONO
CVE-2025-22390HIGH
An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS due to insufficient enforcement of password complexity re
Jan 4, 20257.521NONO
CVE-2025-22387HIGH
An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue exists in requests for resources where the session token is submitted as a URL pa
Jan 4, 20257.521NONO
CVE-2025-22386HIGH
An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity session issue exists in the Commerce B2B application, affecting the longevity of active
Jan 4, 20257.321NONO
CVE-2025-22384HIGH
An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue concerning business logic exists in the Commerce B2B application, which allows st
Jan 4, 20257.521NONO
CVE-2025-22388MEDIUM
An issue was discovered in Optimizely EPiServer.CMS.Core before 12.22.0. A high-severity Stored Cross-Site Scripting (XSS) vulnerability exists in the CMS, allowing malicious actor
Jan 4, 20255.718NONO
CVE-2025-22385MEDIUM
An issue was discovered in Optimizely Configured Commerce before 5.2.2408. For newly created accounts, the Commerce B2B application does not require email confirmation. This medium
Jan 4, 20255.918NONO
CVE-2024-56175MEDIUM
In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from client-side tem
Dec 18, 20246.118NONO
CVE-2025-22383MEDIUM
An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity input validation issue exists in the Commerce B2B application, affecting the Contact Us
Jan 4, 20254.616NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
50%
50%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (83.3%)
High2 (16.7%)
Unknown0 (0.0%)
User Interaction
None5 (41.7%)
Unknown0 (0.0%)
Required7 (58.3%)
Privileges Required
Low4 (33.3%)
High1 (8.3%)
None7 (58.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Optimizely.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Optimizely — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Optimizely's Products

View all 1 CNAs →

Top CWEs