PT-2025-38666 · Sitecore · Sitecore Experience Platform+1

Published

2025-09-21

·

Updated

2025-09-26

·

CVE-2025-53692

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sitecore Experience Manager (XM) versions 9.2 through 10.4 Sitecore Experience Platform (XP) versions 9.2 through 10.4
Description The software contains an Improper Neutralization of Input During Web Page Generation, which allows for Cross-Site Scripting (XSS).
Recommendations Update Sitecore Experience Manager (XM) to a version later than 10.4. Update Sitecore Experience Platform (XP) to a version later than 10.4.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-53692

Affected Products

Sitecore Experience Manager
Sitecore Experience Platform