CVE-2025-27218: Code Injection
Published Feb 20, 2025
·Updated
Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through insecure deserialization.
Affected Software
2 affected components
sitecore Experience Manager (XM)<10.4
sitecore Experience Platform (XP)<10.4
Event History
Feb 20, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Jun 17, 2025
News Published
via BleepingComputer·03:10 PM
Jun 21, 2025
News Published
via BleepingComputer·03:12 PM
Jun 26, 2025
Exploit Published
12:00 AM
Known Exploited
06:33 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-27218?
CVE-2025-27218 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2025-27218?
To fix CVE-2025-27218, update Sitecore Experience Manager (XM) or Experience Platform (XP) to version 10.4 or higher with KB1002844 applied.
3
What products are affected by CVE-2025-27218?
CVE-2025-27218 affects Sitecore Experience Manager (XM) and Experience Platform (XP) versions before 10.4 KB1002844.
4
What type of vulnerability is CVE-2025-27218?
CVE-2025-27218 is a remote code execution vulnerability caused by insecure deserialization.
5
Can I exploit CVE-2025-27218 remotely?
Yes, CVE-2025-27218 can be exploited remotely by attackers due to its nature of allowing remote code execution.