Show filters
28 Total Results
Displaying 1-10 of 28
Sort by:
Attacker Value
High

CVE-2021-42237

Disclosure Date: November 05, 2021 (last updated November 28, 2024)
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.
Attacker Value
Unknown

CVE-2021-38366

Disclosure Date: August 12, 2021 (last updated November 28, 2024)
Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve remote code execution by visiting an uploaded .aspx file at an admin/Packages URL.
Attacker Value
Unknown

CVE-2024-46938

Disclosure Date: September 15, 2024 (last updated September 21, 2024)
An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated attacker can read arbitrary files.
Attacker Value
Unknown

CVE-2023-35813

Disclosure Date: June 17, 2023 (last updated October 08, 2023)
Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.
Attacker Value
Unknown

CVE-2023-33653

Disclosure Date: June 06, 2023 (last updated October 08, 2023)
Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /Applications/Content%20Manager/Execute.aspx?cmd=convert&mode=HTML.
Attacker Value
Unknown

CVE-2023-33652

Disclosure Date: June 06, 2023 (last updated October 08, 2023)
Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /sitecore/shell/Invoke.aspx.
Attacker Value
Unknown

CVE-2023-33651

Disclosure Date: June 06, 2023 (last updated October 08, 2023)
An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initial Release to v13.0 Initial Release allows attackers to bypass authorization rules.
Attacker Value
Unknown

CVE-2023-27068

Disclosure Date: May 23, 2023 (last updated October 08, 2023)
Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationResult.aspx.
Attacker Value
Unknown

CVE-2023-27067

Disclosure Date: May 22, 2023 (last updated October 08, 2023)
Directory Traversal vulnerability in Sitecore Experience Platform through 10.2 allows remote attackers to download arbitrary files via crafted command to download.aspx
Attacker Value
Unknown

CVE-2023-27066

Disclosure Date: May 22, 2023 (last updated October 08, 2023)
Directory Traversal vulnerability in Site Core Experience Platform 10.2 and earlier allows authenticated remote attackers to download arbitrary files via Urlhandle.