Vulnerabilities
Vulnerable Software
CVE-2025-53690
Known exploited
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0.
CVSS Score
9.0
EPSS Score
0.179
Published
2025-09-03
An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated attacker can read arbitrary files.
CVSS Score
7.5
EPSS Score
0.924
Published
2024-09-15


Contact Us

Shodan ® - All rights reserved