CVE-2019-9875: Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability
High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2025-03-26. EPSS: 13.8% chance of exploitation in the next 30 days.
Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in an HTTP POST parameter.
Affected products
- Sitecore CMS: up to and including 9.1
Published 2019-05-31. Last modified 2026-06-17.