📦 Experience Platform

by Sitecore

🔍 What is Experience Platform?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-53690

CRITICAL CVSS 9.0 Sep 3, 2025

This CVE describes a deserialization vulnerability in Sitecore Experience Manager (XM) and Experience Platform (XP) that allows attackers to inject and execute arbitrary code by sending specially craf...

CVE-2025-53693

CRITICAL CVSS 9.8 Sep 3, 2025

This vulnerability allows attackers to poison the cache in Sitecore Experience Manager/Platform by exploiting unsafe reflection. Attackers can potentially execute arbitrary code remotely. Affected use...

CVE-2023-35813

CRITICAL CVSS 9.8 Jun 17, 2023

This critical vulnerability allows remote attackers to execute arbitrary code on affected Sitecore systems without authentication. It affects Sitecore Experience Manager, Experience Platform, and Expe...

CVE-2023-27068

CRITICAL CVSS 9.8 May 23, 2023

CVE-2023-27068 is a critical deserialization vulnerability in Sitecore Experience Platform that allows remote attackers to execute arbitrary code via the ValidationResult.aspx endpoint. This affects a...

CVE-2021-42237

CRITICAL CVSS 9.8 Nov 5, 2021

CVE-2021-42237 is a critical remote code execution vulnerability in Sitecore Experience Platform (XP) that allows unauthenticated attackers to execute arbitrary commands on affected servers through in...

CVE-2025-53691

HIGH CVSS 8.8 Sep 3, 2025

A deserialization vulnerability in Sitecore Experience Manager (XM) and Experience Platform (XP) allows remote attackers to execute arbitrary code by sending specially crafted data. This affects all o...

CVE-2024-46938

HIGH CVSS 7.5 Sep 15, 2024

An unauthenticated attacker can read arbitrary files on Sitecore Experience Platform, Experience Manager, and Experience Commerce systems. This vulnerability affects all versions from 8.0 Initial Rele...

CVE-2023-33651

HIGH CVSS 7.5 Jun 6, 2023

This vulnerability allows attackers to bypass authorization rules in Sitecore's MVC Device Simulator component, potentially accessing restricted functionality or data. It affects Sitecore Experience P...

CVE-2023-33653

HIGH CVSS 8.8 Jun 6, 2023

Sitecore Experience Platform v9.3 contains an authenticated remote code execution vulnerability in the Content Manager component. Attackers with valid credentials can execute arbitrary code on affecte...