CVE-2025-53693: HTML Cache Poisoning through Unsafe Reflections
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Cache Poisoning.This issue affects Sitecore Experience Manager (XM): from 9.0 through 9.3, from 10.0 through 10.4; Experience Platform (XP): from 9.0 through 9.3, from 10.0 through 10.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53693?
CVE-2025-53693 is classified as a medium severity vulnerability due to its potential for cache poisoning.
How do I fix CVE-2025-53693?
To fix CVE-2025-53693, upgrade Sitecore Experience Manager (XM) or Sitecore Experience Platform (XP) to version 10.5 or later.
Which versions are affected by CVE-2025-53693?
CVE-2025-53693 affects Sitecore Experience Manager (XM) and Sitecore Experience Platform (XP) versions from 9.0 to 9.3 and from 10.0 to 10.4.
What is the nature of the vulnerability in CVE-2025-53693?
CVE-2025-53693 involves the use of externally-controlled input that can lead to unsafe reflection, enabling cache poisoning.
Is it safe to use affected versions of Sitecore after CVE-2025-53693 is discovered?
Using affected versions of Sitecore after the discovery of CVE-2025-53693 is not safe as they may be vulnerable to cache poisoning attacks.