Skip to content

Known CVE

Sitecore Experience Platform Pre-Auth RCE

Sitecore XP 7.5 to Sitecore XP 8.2 Update 7 is vulnerable to an insecure deserialization attack where remote commands can be executed by an attacker with no authentication or special configuration required.

CVE-2021-42237

Critical2021CVSS 9.8CWE-502

cve2021 · packetstorm · rce · sitecore · deserialization · oast · kev · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website