CVE-2023-33651: Sitecore Experience Commerce

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initial Release to v13.0 Initial Release allows attackers to bypass authorization rules.

Affected products

  • Sitecore Experience Commerce: from 9.0, up to and including 10.3
  • Sitecore Experience Manager: from 9.0, up to and including 10.3
  • Sitecore Experience Platform: from 9.0, up to and including 10.3
  • Sitecore Managed Cloud: affected versions not specified

Published 2023-06-06. Last modified 2026-06-17.