VendorsSitecoremanaged_cloudall versions
Vulnerabilities

Sitecore Managed Cloud

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2023-35813
Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.
Published 2023-06-17 · Modified
9.8EPSS 0.867
CVE-2025-53693
HTML Cache Poisoning through Unsafe Reflections
Published 2025-09-03 · Analyzed
9.8EPSS 0.148
CVE-2025-53690
Sitecore Products ViewState Deserialization Vulnerability
Published 2025-09-03 · Analyzed
9.0KEVEPSS 0.511
CVE-2025-34511
Sitecore PowerShell Extension RCE via Unrestricted Upload
Published 2025-06-17 · Analyzed
8.8EPSS 0.298
CVE-2025-34510
Sitecore XM, XC, and XP Post-Auth RCE via Zip Slip
Published 2025-06-17 · Analyzed
8.8EPSS 0.243
CVE-2025-53691
Sitecore Experience Remote Code Execution through Insecure Deserialization
Published 2025-09-03 · Analyzed
8.8EPSS 0.016
CVE-2025-34509
Sitecore XM and XP Hardcoded Credentials
Published 2025-06-17 · Modified
7.5EPSS 0.559
CVE-2025-53694
Information Disclosure in ItemServices API
Published 2025-09-03 · Analyzed
7.5EPSS 0.060
CVE-2023-33651
An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initial Release to v13.0 Initial Release allows attackers to bypass authorization rules.
Published 2023-06-06 · Modified
7.5EPSS 0.014