CVE-2019-11080: Sitecore Experience Platform
High severity, CVSS 8.8. EPSS: 13.9% chance of exploitation in the next 30 days.
Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. An authenticated user with necessary permissions is able to remotely execute OS commands by sending a crafted serialized object.
Affected products
- Sitecore Experience Platform: before 9.1.1 (fixed in 9.1.1)
Published 2019-06-06. Last modified 2026-06-17.