CVE-2019-9875: Sitecore CMS and Experience Platform (XP)
EPSS13.7%No. 1215 of 1739 in KEV
CVE year2019~6 yrs before listing
Same vendor in KEV4
Same product2
| Field | Value |
|---|---|
| Vendor | Sitecore |
| Product | CMS and Experience Platform (XP) |
| Name | Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability |
| Added to KEV | 2025-03-26 |
| US federal due date | 2025-04-16 |
| Ransomware use | Unknown |
| CWE | CWE-502 |
CISA description
Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.
Other entries for this product
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2019-9874 | Sitecore CMS and Experience Platform (XP) | 2025-03-26 | 83.7% | Unknown |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Sitecore CMS and Experience Platform (XP) vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-26.