← Back

Sitecore

sitecore

35 CVEs • 10 products

Products (10)

Click to collapse
Toggle
Managed Cloud
managed_cloud
Cms
cms
Crm
crm
Sitecore.net
sitecore.net
Staging Module
staging_module
Rocks
rocks
Sitecore
sitecore

CVEs (35)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sitecore
1Experience Platform
Nov 21, 2024
Jun 6, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. An authenticated user with necessary permissions is able to remotely execute OS commands by s...Show more
Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. An authenticated user with necessary permissions is able to remotely execute OS commands by sending a crafted serialized object.Show less
1Sitecore
1Cms
Nov 7, 2025
May 31, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in an HTTP POST parameter.
1Sitecore
2Cms
Experience Platform
Nov 7, 2025
May 31, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unauthenticated attacker to execute arbitrary code by sending a s...Show more
Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.Show less
1Sitecore
1Rocks
Nov 21, 2024
May 29, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious commands and code via the Sitecore Rocks Hard Rocks Service.
1Sitecore
1Sitecore.net
Nov 21, 2024
Apr 27, 2018
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
An issue was discovered in Sitecore Sitecore.NET 8.1 rev. 151207 Hotfix 141178-1 and above. The 'Log Viewer' application is vulnerable to a directory traversal attack, allowing an attacker to access arbitrary files from...Show more
An issue was discovered in Sitecore Sitecore.NET 8.1 rev. 151207 Hotfix 141178-1 and above. The 'Log Viewer' application is vulnerable to a directory traversal attack, allowing an attacker to access arbitrary files from the host Operating System using a sitecore/shell/default.aspx?xmlcontrol=LogViewerDetails&file= URI. Validation is performed to ensure that the text passed to the 'file' parameter correlates to the correct log file directory. This filter can be bypassed by including a valid log filename and then appending a traditional 'dot dot' style attack.Show less
1Sitecore
1Cms
May 13, 2026
Jul 19, 2017
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
In Sitecore 8.2, there is absolute path traversal via the shell/Applications/Layouts/IDE.aspx fi parameter and the admin/LinqScratchPad.aspx Reference parameter.
1Sitecore
1Cms
May 13, 2026
Jul 19, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Sitecore 8.2, there is reflected XSS in the shell/Applications/Tools/Run Program parameter.
1Sitecore
1Sitecore.net
May 13, 2026
Jun 23, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Sitecore.NET 7.1 through 7.2 has a Cross Site Scripting Vulnerability via the searchStr parameter to the /Search-Results URI.
1Sitecore
1Crm
May 13, 2026
May 23, 2017
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to read arbitrary files via an absolute path traversal attack on sitecore/shell/download.aspx with the file parameter.
1Sitecore
1Crm
May 13, 2026
May 23, 2017
N/A· v4
6.7 MEDIUM· v3
6.5 MEDIUM· v2
The package manager in Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to execute arbitrary ASP code by creating a ZIP archive in which a .asp file has a ..\ in its pathname, visiting sitecore/shel...Show more
The package manager in Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to execute arbitrary ASP code by creating a ZIP archive in which a .asp file has a ..\ in its pathname, visiting sitecore/shell/applications/install/dialogs/Upload%20Package/UploadPackage2.aspx to upload this archive and extract its contents, and visiting a URI under sitecore/ to execute the .asp file.Show less
1Sitecore
1Experience Platform
May 13, 2026
Mar 19, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-Site Scripting (XSS) in "/sitecore/client/Applications/List Manager/Taskpages/Contact list" in Sitecore Experience Platform 8.1 rev. 160519 (8.1 Update-3) allows remote attacks via the Name or Description parameter...Show more
Cross-Site Scripting (XSS) in "/sitecore/client/Applications/List Manager/Taskpages/Contact list" in Sitecore Experience Platform 8.1 rev. 160519 (8.1 Update-3) allows remote attacks via the Name or Description parameter. This is fixed in 8.2 Update-2.Show less
1Sitecore
1Cms
May 6, 2026
Jan 13, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Sitecore CMS before 7.0 Update-4 (rev. 140120) allows remote attackers to inject arbitrary web script or HTML via the xmlcontrol parameter to the default URI. NOTE: some of th...Show more
Cross-site scripting (XSS) vulnerability in Sitecore CMS before 7.0 Update-4 (rev. 140120) allows remote attackers to inject arbitrary web script or HTML via the xmlcontrol parameter to the default URI. NOTE: some of these details are obtained from third party information.Show less
1Sitecore
1Staging Module
Apr 23, 2026
Dec 21, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote attackers to bypass authentication and (1) upload files, (2) download files, (3)...Show more
The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote attackers to bypass authentication and (1) upload files, (2) download files, (3) list directories, and (4) clear the server cache via crafted SOAP requests with arbitrary Username and Password values, possibly related to a direct request.Show less
1Sitecore
1Cms
Apr 23, 2026
Jun 22, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in login/default.aspx in Sitecore CMS before 6.0.2 Update-1 090507 allows remote attackers to inject arbitrary web script or HTML via the sc_error parameter.
1Sitecore
1Cms
Apr 23, 2026
Mar 24, 2009
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the web service in Sitecore CMS 5.3.1 rev. 071114 allows remote authenticated users to gain access to security databases, and obtain administrative and user credentials, via unknown vectors r...Show more
Unspecified vulnerability in the web service in Sitecore CMS 5.3.1 rev. 071114 allows remote authenticated users to gain access to security databases, and obtain administrative and user credentials, via unknown vectors related to SOAP and XML requests.Show less