All 3 CVE vulnerabilities found in Experience Manager (XM), with AI-generated Chinese analysis, references, and POCs.
Vendor: Sitecore
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-53690 | Sitecore Products ViewState Deserialization Vulnerability CWE-502 | 9.0 | Critical | 2025-09-03 |
| CVE-2025-53691 | Sitecore Experience Remote Code Execution through Insecure Deserialization CWE-502 | 8.8 | High | 2025-09-03 |
| CVE-2025-34139 | Sitecore XM/XP/XC and Managed Cloud 8.0 - 10.4 Arbitrary File Read CWE-522 | 7.5 | - | 2025-07-25 |
All 3 known CVE vulnerabilities affecting Experience Manager (XM) with full Chinese analysis, references, and POCs where available.