CVE-2024-46938: Sitecore Experience Commerce

High severity, CVSS 7.5. EPSS: 46.8% chance of exploitation in the next 30 days.

An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated attacker can read arbitrary files.

Affected products

  • Sitecore Experience Commerce: from 8.0, up to and including 10.4
  • Sitecore Experience Manager: from 8.0, up to and including 10.4
  • Sitecore Experience Platform: from 8.0, up to and including 10.4

Published 2024-09-15. Last modified 2026-06-17.