Product:

Experience_platform

(Sitecore)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 14
Date Id Summary Products Score Patch Annotated
2023-06-06 CVE-2023-33651 An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initial Release to v13.0 Initial Release allows attackers to bypass authorization rules. Experience_commerce, Experience_manager, Experience_platform, Managed_cloud 7.5
2023-06-06 CVE-2023-33652 Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /sitecore/shell/Invoke.aspx. Experience_platform 8.8
2023-06-06 CVE-2023-33653 Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /Applications/Content%20Manager/Execute.aspx?cmd=convert&mode=HTML. Experience_platform 8.8
2023-06-17 CVE-2023-35813 Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3. Experience_commerce, Experience_manager, Experience_platform, Managed_cloud 9.8