Looking for the vulnerability index of Invicti's legacy products?
Sitecore XM/XP Insecure Deserialization (CVE-2025-27218) - Vulnerability Database

Sitecore XM/XP Insecure Deserialization (CVE-2025-27218)

Description

Due to the insecure BinaryFormatter deserialization vulnerability in Sitecore XM/XP, an unauthenticated attacker might send a specially-crafted serialized request to execute arbitrary code on the system.

Remediation

Upgrade to the latest version of Sitecore

Related Vulnerabilities