Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sitecore

First CVE: Mar 24, 2009Active for: 17 yearsTotal CVEs: 35
75.9
VTI Score
TOP TARGET

Sitecore develops a focused suite of enterprise content-management and commerce platforms—including its Experience Platform, Experience Manager, Experience Commerce, and managed cloud offerings—that serve as centralized hubs for digital experiences and customer data across organizations. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, have an elevated tendency to be confirmed as exploited in the wild and cataloged by CISA, and frequently acquire public exploit code. The exposure recurs across the platform portfolio through high-impact weakness classes including untrusted deserialization, cross-site scripting, path traversal, and unrestricted file uploads, which reflect the complexity of web-facing CMS and integration layers handling user input and file management. Given the vendor's role in managing customer-facing digital infrastructure, these vulnerabilities carry broad downstream risk; defenders should prioritize patching coordinated advisories affecting these platforms and restrict internet exposure where possible. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
35
Total CVEs
More Total CVEs than 98% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked vendors
11.4%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Sitecore over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 24, 2009
17 years ago
Most Recent CVE
Sep 3, 2025
324 days ago

Products(10 total)

Top CVEs

Signals from CVEs in this vendor scope (35 CVEs).

35 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-42237CRITICAL
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the mach
Nov 5, 20219.898YESYES
CVE-2019-9874CRITICAL
Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unauthenticated attacker
May 31, 20199.896YESYES
CVE-2025-53690CRITICAL
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (
Sep 3, 20259.085YESNO
CVE-2023-35813CRITICAL
Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.
Jun 17, 20239.885NOYES
CVE-2019-9875HIGH
Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in
May 31, 20198.874YESNO
CVE-2025-34509HIGH
Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 011967 PRE, and 10.4 to 10.4.1 rev.
Jun 17, 20257.566NOYES
CVE-2024-46938HIGH
An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthentic
Sep 15, 20247.561NOYES
CVE-2025-34511HIGH
Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an unrestricted file upload issue.
Jun 17, 20258.845NOYES
CVE-2025-34510HIGH
Sitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10.0 through 10.4 are affected by a Zip Slip vulnerability. A
Jun 17, 20258.845NOYES
CVE-2019-11080HIGH
Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. An authenticated user with necessary permissions is a
Jun 6, 20198.843NOYES
View all 35 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products35 CVEs
37%
43%
20%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (2.9%)
Network30 (85.7%)
Unknown4 (11.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low30 (85.7%)
High1 (2.9%)
Unknown4 (11.4%)
User Interaction
None26 (74.3%)
Unknown4 (11.4%)
Required5 (14.3%)
Privileges Required
Low11 (31.4%)
High4 (11.4%)
None16 (45.7%)
Unknown4 (11.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (35 CVEs).

CISA KEV
4 CVEs
11.4% of CVEs· 100th percentile
Metasploit
3 CVEs
8.6% of CVEs· 98th percentile
Nuclei
6 CVEs
17.1% of CVEs· 97th percentile
ExploitDB
6 CVEs
17.1% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sitecore.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sitecore — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sitecore's Products

View all 3 CNAs →

Top CWEs