CVE-2019-12440: Sitecore Rocks
Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.
The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious commands and code via the Sitecore Rocks Hard Rocks Service.
Affected products
- Sitecore Rocks: before 2.1.149 (fixed in 2.1.149)
Published 2019-05-29. Last modified 2026-06-17.