Sitecore develops a focused suite of enterprise content-management and commerce platforms—including its Experience Platform, Experience Manager, Experience Commerce, and managed cloud offerings—that serve as centralized hubs for digital experiences and customer data across organizations. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, have an elevated tendency to be confirmed as exploited in the wild and cataloged by CISA, and frequently acquire public exploit code. The exposure recurs across the platform portfolio through high-impact weakness classes including untrusted deserialization, cross-site scripting, path traversal, and unrestricted file uploads, which reflect the complexity of web-facing CMS and integration layers handling user input and file management. Given the vendor's role in managing customer-facing digital infrastructure, these vulnerabilities carry broad downstream risk; defenders should prioritize patching coordinated advisories affecting these platforms and restrict internet exposure where possible. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sitecore over time
Signals from CVEs in this vendor scope (35 CVEs).
35 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-42237CRITICAL Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the mach | Nov 5, 2021 | 9.8 | 98 | YES | YES |
CVE-2019-9874CRITICAL Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unauthenticated attacker | May 31, 2019 | 9.8 | 96 | YES | YES |
CVE-2025-53690CRITICAL Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager ( | Sep 3, 2025 | 9.0 | 85 | YES | NO |
CVE-2023-35813CRITICAL Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3. | Jun 17, 2023 | 9.8 | 85 | NO | YES |
CVE-2019-9875HIGH Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in | May 31, 2019 | 8.8 | 74 | YES | NO |
CVE-2025-34509HIGH Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 011967 PRE, and 10.4 to 10.4.1 rev. | Jun 17, 2025 | 7.5 | 66 | NO | YES |
CVE-2024-46938HIGH An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthentic | Sep 15, 2024 | 7.5 | 61 | NO | YES |
CVE-2025-34511HIGH Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an unrestricted file upload issue. | Jun 17, 2025 | 8.8 | 45 | NO | YES |
CVE-2025-34510HIGH Sitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10.0 through 10.4 are affected by a Zip Slip vulnerability. A | Jun 17, 2025 | 8.8 | 45 | NO | YES |
CVE-2019-11080HIGH Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. An authenticated user with necessary permissions is a | Jun 6, 2019 | 8.8 | 43 | NO | YES |
Signals from CVEs in this vendor scope (35 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sitecore.
Media articles that mention a CVE ID that affects a product developed by Sitecore — matched by CVE ID, not by vendor name.