CVE-2025-53693
Sitecore Experience Platform (XP) vulnerability analysis and mitigation

Overview

CVE-2025-53693 is an unauthenticated server-side cache poisoning vulnerability affecting Sitecore Experience Manager (XM) and Sitecore Experience Platform (XP). The vulnerability was discovered by researcher Piotr Bazydlo and disclosed in August 2025. The affected versions include Sitecore Experience Manager (XM) versions 9.0 through 9.3 and 10.0 through 10.4, as well as Experience Platform (XP) versions 9.0 through 9.3 and 10.0 through 10.4. The vulnerability has been assigned a CVSS v3.1 base score of 9.8 (Critical) (WatchTowr Labs, AttackerKB).

Technical details

The vulnerability stems from unsafe reflection in the HTML cache mechanism of Sitecore. An attacker can exploit this by sending specially crafted HTTP requests to the XamlPageHandlerFactory, which allows for manipulation of cached HTML content through the AddToCache method. The vulnerability specifically involves the ability to call methods dynamically through reflection, with the attack path requiring interaction with the AjaxScriptManager and GlobalHeader control. The vulnerability is tracked as CWE-470 (Use of Externally-Controlled Input to Select Classes or Code) (WatchTowr Labs).

Impact

Successful exploitation of this vulnerability allows an unauthenticated attacker to perform HTML cache poisoning, potentially leading to the compromise of cached web content served to users. When chained with other vulnerabilities, it could potentially lead to remote code execution. The vulnerability is particularly concerning as Sitecore is widely used by major organizations, with at least 22,000 Sitecore instances identified on the internet (WatchTowr Labs).

Mitigation and workarounds

Patches for this vulnerability were released by Sitecore in June 2025. Organizations running affected versions of Sitecore Experience Manager (XM) or Sitecore Experience Platform (XP) should apply the available security updates immediately. Systems with caching enabled should be prioritized for patching, as they are particularly vulnerable to exploitation (Hacker News).

Additional resources


SourceThis report was generated using AI

Related Sitecore Experience Platform (XP) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-53693CRITICAL9.8
  • Sitecore Experience Platform (XP)Sitecore Experience Platform (XP)
  • cpe:2.3:a:sitecore:experience_platform
NoNoSep 03, 2025
CVE-2025-53690CRITICAL9
  • Sitecore Experience Platform (XP)Sitecore Experience Platform (XP)
  • cpe:2.3:a:sitecore:experience_platform
YesNoSep 03, 2025
CVE-2025-53691HIGH8.8
  • Sitecore Experience Platform (XP)Sitecore Experience Platform (XP)
  • cpe:2.3:a:sitecore:experience_platform
NoNoSep 03, 2025
CVE-2025-34511HIGH8.8
  • Sitecore Experience Platform (XP)Sitecore Experience Platform (XP)
  • cpe:2.3:a:sitecore:experience_platform
NoNoJun 17, 2025
CVE-2025-53694HIGH7.5
  • Sitecore Experience Platform (XP)Sitecore Experience Platform (XP)
  • cpe:2.3:a:sitecore:experience_platform
NoNoSep 03, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management