Sitecore vendor intelligence
Sitecore Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Sitecore products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 7
- Known exploited vulnerabilities affecting Sitecore products
- In CISA KEV
- 4
- Records also listed in the official catalog
- Beyond CISA KEV
- 3
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 0
- Sitecore KEVs with sensor-observed exploitation activity
The catalog gap matters for Sitecore exposure
Three of the seven exploited Sitecore CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 43% of this vendor portfolio.
- 57%
- Covered by CISA
- 43%
- Beyond CISA
- 7
- Product families
Attested Sitecore CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-34509
Sitecore XM and XP Hardcoded Credentials |
Experience Manager, Experience Platform | High | Beyond CISA | 30 Apr 2026 |
|
CVE-2024-46938
An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through... |
Experience Platform, Experience Manager, Experience Commerce | High | Beyond CISA | 24 Jul 2025 |
|
CVE-2023-35813
Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3. |
Experience Manager, Experience Platform, Experience Commerce | High | Beyond CISA | 01 Jul 2025 |
|
CVE-2025-53690
Sitecore Products ViewState Deserialization Vulnerability |
Experience Manager (XM), Experience Platform (XP) | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2021-42237
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve... |
Sitecore XP | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2019-9874
Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2... |
CMS | Confirmed | In CISA | 26 Mar 2025 |
|
CVE-2019-9875
Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by... |
Sitecore CMS | Confirmed | In CISA | 26 Mar 2025 |
No Sitecore CVEs match this search or filter.
Showing 7 of 7 Sitecore known exploited vulnerabilities.
Recurring weakness patterns
Deserialization, exposure, and use account for six mapped occurrences across this Sitecore KEV portfolio.
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.