CVE-2025-53691
Sitecore Experience Platform (XP) vulnerability analysis and mitigation

Overview

A critical vulnerability (CVE-2025-53691) has been identified in Sitecore Experience Manager (XM) and Experience Platform (XP) that allows remote code execution through insecure deserialization. The vulnerability affects XM versions 9.0 through 9.3 and 10.0 through 10.4, as well as XP versions 9.0 through 9.3 and 10.0 through 10.4. The flaw was discovered in June 2025 and patches were released by Sitecore in the same month (WatchTowr Labs, Hacker News).

Technical details

The vulnerability exists in the BinaryFormatter.Deserialize() method within the Sitecore.Convert.Base64ToObject() function, which processes base64-encoded objects without proper validation. The exploit chain targets the ConvertToRuntimeHtml pipeline, specifically focusing on iframe elements with embedded serialized payloads. When the FixHtmlPage control processes malicious HTML containing iframe tags with id and value attributes, it triggers the vulnerable deserialization path. The vulnerability has been assigned a CVSS v3 base score of 8.8 (High), with an impact score of 5.9 and exploitability score of 2.8 (AttackerKB).

Impact

Successful exploitation of CVE-2025-53691 can lead to complete system compromise when chained with other vulnerabilities like HTML cache poisoning (CVE-2025-53693). The vulnerability affects thousands of enterprise installations worldwide, potentially exposing sensitive data and allowing attackers to execute arbitrary code on affected systems (Cybersecurity News).

Mitigation and workarounds

Sitecore has released security patches for the vulnerability in June 2025. Organizations using affected versions of Sitecore Experience Manager (XM) and Experience Platform (XP) should immediately apply the available security updates. Additionally, organizations should review their ItemServices API exposure to prevent exploitation (Hacker News).

Additional resources


SourceThis report was generated using AI

Related Sitecore Experience Platform (XP) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-53693CRITICAL9.8
  • Sitecore Experience Platform (XP)Sitecore Experience Platform (XP)
  • cpe:2.3:a:sitecore:experience_platform
NoNoSep 03, 2025
CVE-2025-53690CRITICAL9
  • Sitecore Experience Platform (XP)Sitecore Experience Platform (XP)
  • cpe:2.3:a:sitecore:experience_platform
YesNoSep 03, 2025
CVE-2025-53691HIGH8.8
  • Sitecore Experience Platform (XP)Sitecore Experience Platform (XP)
  • cpe:2.3:a:sitecore:experience_platform
NoNoSep 03, 2025
CVE-2025-34511HIGH8.8
  • Sitecore Experience Platform (XP)Sitecore Experience Platform (XP)
  • cpe:2.3:a:sitecore:experience_platform
NoNoJun 17, 2025
CVE-2025-53694HIGH7.5
  • Sitecore Experience Platform (XP)Sitecore Experience Platform (XP)
  • cpe:2.3:a:sitecore:experience_platform
NoNoSep 03, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management