CRITICAL

CVE-2025-53690

Sitecore Experience Commerce 2025-09-03 CVSS v3.1
CVSS
9
KEV

Description

Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0.

Summary dbcve.org

A deserialization of untrusted data vulnerability in Sitecore Experience Manager (XM) and Experience Platform (XP) allows attackers to inject malicious code through unsafe deserialization. This affects all versions through 9.0, enabling remote code execution due to the lack of proper validation on deserialized data.

Mitigation

Upgrade to a patched version of Sitecore XP/XM beyond 9.0, or implement input validation and secure serialization practices on data streams entering the deserialization endpoints. Network segmentation may reduce attack surface while remediation is planned.

Proof of Concept

Weakness (CWE)

CWE-502 Deserialization of Untrusted Data

EPSS Score

51.09%
Probability of exploitation in next 30 days
98.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE