CVE-2025-34138
Sitecore XM/XP/XC and Managed Cloud 9.2 - 10.4 RCE
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability exists in Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud that could allow remote code execution or unauthorized access to information. This vulnerability affects all Experience Platform topologies (XM, XP, XC) from 9.2 Initial Release through 10.4 Initial Release. PaaS and containerized solutions are similarly affected.
Existe una vulnerabilidad en Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC) y Managed Cloud que podría permitir la ejecución remota de código o el acceso no autorizado a la información. Esta vulnerabilidad afecta a todas las topologías de Experience Platform (XM, XP, XC) desde la versión inicial 9.2 hasta la versión inicial 10.4. Las soluciones PaaS y en contenedores se ven afectadas de forma similar.
A vulnerability exists in Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud that could allow remote code execution or unauthorized access to information. This vulnerability affects all Experience Platform topologies (XM, XP, XC) from 9.2 Initial Release through 10.4 Initial Release. PaaS and containerized solutions are similarly affected.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2025-04-15 CVE Reserved
- 2025-07-25 CVE Published
- 2025-07-29 CVE Updated
- 2025-08-26 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://www.vulncheck.com/advisories/sitecore-xm-xp-xc-managed-cloud-rce | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1003734 | 2025-07-25 | |
https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1003743 | 2025-07-25 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sitecore Search vendor "Sitecore" | Experience Commerce Search vendor "Sitecore" for product "Experience Commerce" | * | - |
Affected
| ||||||
Sitecore Search vendor "Sitecore" | Experience Manager Search vendor "Sitecore" for product "Experience Manager" | * | - |
Affected
| ||||||
Sitecore Search vendor "Sitecore" | Experience Platform Search vendor "Sitecore" for product "Experience Platform" | * | - |
Affected
| ||||||
Sitecore Search vendor "Sitecore" | Managed Cloud Search vendor "Sitecore" for product "Managed Cloud" | * | - |
Affected
|