VYPR
Unrated severityCISA KEVNVD Advisory· Published Sep 3, 2025· Updated Feb 26, 2026

Sitecore Products ViewState Deserialization Vulnerability

CVE-2025-53690

Description

Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0.

Affected products

2
  • Sitecore/Experience Manager (XM)v5
    Range: 0
  • Sitecore/Experience Platform (XP)v5
    Range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.