Vulnerabilities (CVE)

Filtered by vendor Sitecore Subscribe
Filtered by product Experience Platform
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-42237 1 Sitecore 1 Experience Platform 2021-12-03 10.0 HIGH 9.8 CRITICAL
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.
CVE-2019-9874 1 Sitecore 2 Cms, Experience Platform 2019-06-03 7.5 HIGH 9.8 CRITICAL
Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.