
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-53693 is an unauthenticated server-side cache poisoning vulnerability affecting Sitecore Experience Manager (XM) and Sitecore Experience Platform (XP). The vulnerability was discovered by researcher Piotr Bazydlo and disclosed in August 2025. The affected versions include Sitecore Experience Manager (XM) versions 9.0 through 9.3 and 10.0 through 10.4, as well as Experience Platform (XP) versions 9.0 through 9.3 and 10.0 through 10.4. The vulnerability has been assigned a CVSS v3.1 base score of 9.8 (Critical) (WatchTowr Labs, AttackerKB).
The vulnerability stems from unsafe reflection in the HTML cache mechanism of Sitecore. An attacker can exploit this by sending specially crafted HTTP requests to the XamlPageHandlerFactory, which allows for manipulation of cached HTML content through the AddToCache method. The vulnerability specifically involves the ability to call methods dynamically through reflection, with the attack path requiring interaction with the AjaxScriptManager and GlobalHeader control. The vulnerability is tracked as CWE-470 (Use of Externally-Controlled Input to Select Classes or Code) (WatchTowr Labs).
Successful exploitation of this vulnerability allows an unauthenticated attacker to perform HTML cache poisoning, potentially leading to the compromise of cached web content served to users. When chained with other vulnerabilities, it could potentially lead to remote code execution. The vulnerability is particularly concerning as Sitecore is widely used by major organizations, with at least 22,000 Sitecore instances identified on the internet (WatchTowr Labs).
Patches for this vulnerability were released by Sitecore in June 2025. Organizations running affected versions of Sitecore Experience Manager (XM) or Sitecore Experience Platform (XP) should apply the available security updates immediately. Systems with caching enabled should be prioritized for patching, as they are particularly vulnerable to exploitation (Hacker News).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."