CVE-2023-35813
Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.
- Published
- Jun 17, 2023
- Updated
- Dec 17, 2024
- Assigning CNA
- mitre
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.7%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.
Sources
5- CVE-2023-35813-PoCExploit
An exploit for the Sitecore Remote Code Execution Vulnerability
- CVE-2023-35813Exploit
Exploit for CVE-2023-35813 POC
Proof-of-concept script to detect vulnerable Sitecore instances by analyzing server response headers for specific modifications, aiding in vulnerability assessment.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.