Critical severity9.8NVD Advisory· Published May 29, 2019· Updated Jun 17, 2026
CVE-2019-12440
CVE-2019-12440
Description
The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious commands and code via the Sitecore Rocks Hard Rocks Service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Sitecore/Rocks plugindescription
- Range: <2.1.149
Patches
Vulnerability mechanics
References
3- github.com/Sitecore/Sitecore.Rocks/compare/be79dcc...bd9ba6anvdPatchThird Party Advisory
- kb.sitecore.net/articles/842902nvdPatchVendor Advisory
- github.com/Sitecore/Sitecore.Rocks/releases/tag/2.1.149nvdRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.