Home/Product/sitecore experience commerce
Product

sitecore experience commerce

10 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-53690
<= 9.0
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code
9.0CRITICAL
CVE-2025-53694
>= 9.2 and <= 10.4
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Experience Manager (XM), Sitecore Ex
7.5HIGH
CVE-2025-53693
>= 9.0 and <= 10.4
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Experience M
9.8CRITICAL
CVE-2025-53691
>= 9.0 and <= 10.4
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Remo
8.8HIGH
CVE-2025-34511
>= 9.0 and <= 10.4
Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is
8.8HIGH
CVE-2025-34510
>= 9.0 and <= 10.4
Sitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10.0 through
8.8HIGH
CVE-2025-34509
>= 9.0 and <= 10.4
Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3
7.5HIGH
CVE-2024-46938
>= 8.0 and <= 10.4
An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Re
7.5HIGH
CVE-2023-35813
>= 8.2 and <= 10.3
Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Comme
9.8CRITICAL
CVE-2023-33651
>= 9.0 and <= 10.3
An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v
7.5HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin