← Back to browse · API

CVE-2025-53693

Severity
CRITICAL
CVSS
9.8
EPSS
0.14117
Risk score
44.14
CISA KEV
No
PoC
No
Published
2025-09-03
Modified
2025-09-03
First seen
2026-08-07
Aliases
EUVD-2025-26500, GHSA-6JJ2-MFWJ-34Q5
Products
Sitecore:Experience Platform (XP) 10.0 ≤10.4, Sitecore:Experience Platform (XP) 9.0 ≤9.3, Sitecore:Sitecore Experience Manager (XM) 10.0 ≤10.4, Sitecore:Sitecore Experience Manager (XM) 9.0 ≤9.3
Sources
euvd EUVD-2025-26500

Description

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Cache Poisoning.This issue affects Sitecore Experience Manager (XM): from 9.0 through 9.3, from 10.0 through 10.4; Experience Platform (XP): from 9.0 through 9.3, from 10.0 through 10.4.

References