Sitecore Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Sitecore products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

7

In CISA KEV

4

Beyond CISA KEV

3

Sensor Observed

0

Virtual Patch Available

0

Sitecore KEVs Added by Year

Loading...

7 Sitecore KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2025-34509

Sitecore XM and XP Hardcoded Credentials

High Not in CISA 30 Apr 2026
CVE-2024-46938

An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through...

High Not in CISA 24 Jul 2025
CVE-2023-35813

Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.

High Not in CISA 01 Jul 2025
CVE-2025-53690

Sitecore Products ViewState Deserialization Vulnerability

Confirmed In CISA 01 Jun 2026
CVE-2021-42237

Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve...

Confirmed In CISA 25 Mar 2022
CVE-2019-9874

Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2...

Confirmed In CISA 26 Mar 2025
CVE-2019-9875

Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by...

Confirmed In CISA 26 Mar 2025

Common Vulnerability Classes (CWE)

  • CWE-502 — Deserialization of Untrusted Data 4
  • CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor 1
  • CWE-798 — Use of Hard-coded Credentials 1
  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology