VYPR

Experience Platform (XP)

by Sitecore

CVEs (26)

  • CVE-2015-10142MedJul 25, 2025
    risk 0.45cvss epss 0.00

    Sitecore Experience Platform (XP) prior to 8.0 Initial Release (rev. 141212) and Content Management System (CMS) prior to 7.2 Update-3 (rev. 141226) and prior to 7.5 Update-1 (rev. 150130) contain a vulnerability that may allow an attacker to download files under the web root…

  • CVE-2025-27218MedFeb 20, 2025
    risk 0.43cvss 5.3epss 0.65

    Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through insecure deserialization.

  • CVE-2016-8855MedMar 19, 2017
    risk 0.43cvss 6.1epss 0.02

    Cross-Site Scripting (XSS) in "/sitecore/client/Applications/List Manager/Taskpages/Contact list" in Sitecore Experience Platform 8.1 rev. 160519 (8.1 Update-3) allows remote attacks via the Name or Description parameter. This is fixed in 8.2 Update-2.

  • CVE-2023-27066MedMay 22, 2023
    risk 0.42cvss 6.5epss 0.01

    Directory Traversal vulnerability in Site Core Experience Platform 10.2 and earlier allows authenticated remote attackers to download arbitrary files via Urlhandle.

  • CVE-2019-13493MedJul 17, 2019
    risk 0.38cvss 5.4epss 0.02

    In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user can modify the uploaded file extension parameter to inject arbitrary JavaScript.

  • CVE-2022-4979MedJul 25, 2025
    risk 0.33cvss epss 0.01

    A cross-site scripting (XSS) vulnerability exists in Sitecore Experience Platform (XP) 7.5 - 10.2 and CMS 7.2 - 7.2 Update-6 that may allow authenticated Sitecore Shell users to be tricked into executing custom JS code. Managed Cloud Standard customers who run the affected…

Page 2 of 2