A vulnerability exists in Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud that could allow remote code execution or unauthorized access to information. This vulnerability affects all Experience Platform topologies (XM, XP, XC) from 9.2 Initial Release through 10.4 Initial Release. PaaS and containerized solutions are similarly affected.
Metrics
Affected Vendors & Products
References
History
Thu, 31 Jul 2025 10:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Sitecore
Sitecore experience Commerce Sitecore experience Manager Sitecore experience Platform Sitecore managed Cloud |
|
Vendors & Products |
Sitecore
Sitecore experience Commerce Sitecore experience Manager Sitecore experience Platform Sitecore managed Cloud |
Fri, 25 Jul 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-94 | |
Metrics |
ssvc
|
Fri, 25 Jul 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability exists in Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud that could allow remote code execution or unauthorized access to information. This vulnerability affects all Experience Platform topologies (XM, XP, XC) from 9.2 Initial Release through 10.4 Initial Release. PaaS and containerized solutions are similarly affected. | |
Title | Sitecore XM/XP/XC and Managed Cloud 9.2 - 10.4 RCE | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-07-25T15:54:47.306Z
Updated: 2025-07-25T18:16:54.406Z
Reserved: 2025-04-15T19:15:22.562Z
Link: CVE-2025-34138

Updated: 2025-07-25T18:16:51.431Z

Status : Awaiting Analysis
Published: 2025-07-25T16:15:28.790
Modified: 2025-07-29T14:14:55.157
Link: CVE-2025-34138

No data.