Sitecore vendor intelligence

Sitecore Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Sitecore products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Total KEVs
7
Known exploited vulnerabilities affecting Sitecore products
In CISA KEV
4
Records also listed in the official catalog
Beyond CISA KEV
3
Additional exploited CVEs absent from CISA KEV
Sensor Observed
0
Sitecore KEVs with sensor-observed exploitation activity

The catalog gap matters for Sitecore exposure

Three of the seven exploited Sitecore CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 43% of this vendor portfolio.

57%
Covered by CISA
43%
Beyond CISA
7
Product families

Attested Sitecore CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2025-34509

Sitecore XM and XP Hardcoded Credentials

Experience Manager, Experience Platform High Beyond CISA 30 Apr 2026
CVE-2024-46938

An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through...

Experience Platform, Experience Manager, Experience Commerce High Beyond CISA 24 Jul 2025
CVE-2023-35813

Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.

Experience Manager, Experience Platform, Experience Commerce High Beyond CISA 01 Jul 2025
CVE-2025-53690

Sitecore Products ViewState Deserialization Vulnerability

Experience Manager (XM), Experience Platform (XP) Confirmed In CISA 01 Jun 2026
CVE-2021-42237

Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve...

Sitecore XP Confirmed In CISA 25 Mar 2022
CVE-2019-9874

Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2...

CMS Confirmed In CISA 26 Mar 2025
CVE-2019-9875

Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by...

Sitecore CMS Confirmed In CISA 26 Mar 2025

Showing 7 of 7 Sitecore known exploited vulnerabilities.

Recurring weakness patterns

Deserialization, exposure, and use account for six mapped occurrences across this Sitecore KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.