Known vulnerabilities in Experience Manager
Vendor:
Sitecore
Software:
Experience Manager
Software CPE:
cpe:2.3:a:sitecore:experience_manager:*:*:*:*:*:*:*:*
Website:
https://www.sitecore.com/
Total vulnerabilities:
6
Public exploits:
2
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU118743 - Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') CVE-2025-3600 |
CWE-470 | Medium | - | 25.11.2025 |
SB2025112527 SB2025112528 |
||
| #VU118742 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2025-53692 |
CWE-79 | Low | - | 25.11.2025 |
SB2025112521 |
||
| #VU118741 - Exposure of sensitive information to an unauthorized actor CVE-2025-53694 |
CWE-200 | Medium | - | 25.11.2025 |
SB2025112521 |
||
| #VU118740 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
CWE-22 | High | - | 25.11.2025 |
SB2025112520 |
||
| #VU116778 - Deserialization of Untrusted Data CVE-2025-27218 |
CWE-502 | Critical | 10.4.0.010422, 10.4.1.012149 | 08.10.2025 |
SB2025100883 |
||
| #VU114796 - Deserialization of Untrusted Data CVE-2025-53690 |
CWE-502 | Critical | - | 04.09.2025 |
SB2025090436 |