CVE-2023-35813: Sitecore Experience Commerce

Critical severity, CVSS 9.8. EPSS: 86.7% chance of exploitation in the next 30 days.

Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.

Affected products

  • Sitecore Experience Commerce: from 8.2, up to and including 10.3
  • Sitecore Experience Manager: from 8.2, up to and including 10.3
  • Sitecore Experience Platform: from 8.2, up to and including 10.3
  • Sitecore Managed Cloud: from 8.2, up to and including 10.3

Published 2023-06-17. Last modified 2026-06-17.