PT-2025-35313 · Sitecore · Sitecore Experience Platform+1

Piotr Bazydlo

·

Published

2025-08-29

·

Updated

2025-09-08

·

CVE-2025-53691

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sitecore Experience Manager (XM) versions 9.0 through 9.3, 10.0 through 10.4 Sitecore Experience Platform (XP) versions 9.0 through 9.3, 10.0 through 10.4
Description A deserialization of untrusted data issue exists in Sitecore Experience Manager (XM) and Sitecore Experience Platform (XP), potentially allowing for Remote Code Execution (RCE).
Recommendations Sitecore Experience Manager (XM) versions 9.0 through 9.3 should be updated. Sitecore Experience Manager (XM) versions 10.0 through 10.4 should be updated. Sitecore Experience Platform (XP) versions 9.0 through 9.3 should be updated. Sitecore Experience Platform (XP) versions 10.0 through 10.4 should be updated.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-53691

Affected Products

Sitecore Experience Manager
Sitecore Experience Platform