CVE-2025-53690
Sitecore Products ViewState Deserialization Vulnerability
- Published
- Sep 3, 2025
- Updated
- Feb 26, 2026
- Assigning CNA
- Wiz
- Evidence observed
- Sep 4, 2025
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 98.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0.
Sources
3- CVE-2025-53690-POCDetection
CVE-2025-53690 POC
- CVE-2025-53690-AnalysisResearch
This is CVE-2025-53690 Analysis Documents.
- CVE-2025-53690Detection
Detection for CVE-2025-53690
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.