Known Vulnerabilities for products from Sitecore

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Sitecore".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2023-35813 json Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience ... 9.8 - CRITICAL 2023-06-17 2023-06-30
CVE-2023-33653 json Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability v... 8.8 - HIGH 2023-06-06 2023-06-14
CVE-2023-33652 json Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability v... 8.8 - HIGH 2023-06-06 2023-06-14
CVE-2023-33651 json An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (... 7.5 - HIGH 2023-06-06 2023-06-16
CVE-2023-27068 json Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code ... 9.8 - CRITICAL 2023-05-23 2023-05-30
CVE-2023-27067 json Directory Traversal vulnerability in Sitecore Experience Platform through 10.2 allows remote attackers to download arbitrary ... 7.5 - HIGH 2023-05-22 2023-05-27
CVE-2023-27066 json Directory Traversal vulnerability in Site Core Experience Platform 10.2 and earlier allows authenticated remote attackers to ... 6.5 - MEDIUM 2023-05-22 2023-05-27
CVE-2023-26262 json An issue was discovered in Sitecore XP/XM 10.3. As an authenticated Sitecore user, a unrestricted language file upload vulner... 7.2 - HIGH 2023-03-14 2023-04-10
CVE-2021-42237 json Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is p... Not Provided 2021-11-05 2026-07-09
CVE-2021-38366 json Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve... 8.8 - HIGH 2021-08-12 2021-08-25
CVE-2019-13493 json In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user c... 5.4 - MEDIUM 2019-07-17 2019-07-18
CVE-2019-12440 json The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious commands and... 9.8 - CRITICAL 2019-05-29 2020-08-24
CVE-2019-11198 json Multiple cross-site scripting (XSS) vulnerabilities in Sitecore CMS 9.0.1 and earlier allow remote attackers to inject arbitr... 6.1 - MEDIUM 2019-08-05 2019-08-13
CVE-2019-11080 json Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863... 8.8 - HIGH 2019-06-06 2019-06-13
CVE-2019-9875 json Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute... 8.8 - HIGH 2019-05-31 2019-06-03
CVE-2019-9874 json Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sit... 9.8 - CRITICAL 2019-05-31 2019-06-03
CVE-2018-7669 json An issue was discovered in Sitecore Sitecore.NET 8.1 rev. 151207 Hotfix 141178-1 and above. The 'Log Viewer' application is v... 7.5 - HIGH 2018-04-27 2018-08-11
CVE-2017-11440 json In Sitecore 8.2, there is absolute path traversal via the shell/Applications/Layouts/IDE.aspx fi parameter and the admin/Linq... Not Provided 2017-07-19 2025-04-20
CVE-2017-11439 json In Sitecore 8.2, there is reflected XSS in the shell/Applications/Tools/Run Program parameter. Not Provided 2017-07-19 2025-04-20
CVE-2017-9356 json Sitecore.NET 7.1 through 7.2 has a Cross Site Scripting Vulnerability via the searchStr parameter to the /Search-Results URI. Not Provided 2017-06-23 2025-04-20

Known software with vulnerabilities from Sitecore

Type Vendor Product Version
ApplicationSitecoreCms7.0
ApplicationSitecoreCrm8.0
ApplicationSitecoreExperience Platform8.0
ApplicationSitecoreRocks1.1.0
ApplicationSitecoreSitecore.net7.0

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report