CVE-2025-53694: Information Disclosure in ItemServices API
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP).This issue affects Sitecore Experience Manager (XM): from 9.2 through 10.4; Experience Platform (XP): from 9.2 through 10.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53694?
CVE-2025-53694 has a high severity level due to the potential exposure of sensitive information to unauthorized users.
How do I fix CVE-2025-53694?
To fix CVE-2025-53694, update your Sitecore Experience Manager (XM) or Experience Platform (XP) to the latest version beyond 10.4.
Which versions are affected by CVE-2025-53694?
CVE-2025-53694 affects Sitecore Experience Manager (XM) and Experience Platform (XP) versions from 9.2 to 10.4.
What types of information could be exposed due to CVE-2025-53694?
CVE-2025-53694 could expose sensitive user information, including personal data and configuration settings, to unauthorized actors.
Is there a patch available for CVE-2025-53694?
A patch is available as part of the update that users need to apply to secure their installations against CVE-2025-53694.