Unrated severityNVD Advisory· Published Sep 3, 2025· Updated Sep 3, 2025
Information Disclosure in ItemServices API
CVE-2025-53694
Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP).This issue affects Sitecore Experience Manager (XM): from 9.2 through 10.4; Experience Platform (XP): from 9.2 through 10.4.
Affected products
4- Range: 9.2 through 10.4
- Range: 9.2 through 10.4
- Sitecore/Experience Platform (XP)v5Range: 9.2
- Sitecore/Sitecore Experience Manager (XM)v5Range: 9.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.