CVE-2025-34511: Sitecore Experience Commerce
High severity, CVSS 8.8. EPSS: 29.8% chance of exploitation in the next 30 days.
Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an unrestricted file upload issue. A remote, authenticated attacker can upload arbitrary files to the server using crafted HTTP requests, resulting in remote code execution.
Affected products
- Sitecore Experience Commerce: from 9.0, up to and including 10.4
- Sitecore Experience Manager: from 9.0, up to and including 10.4
- Sitecore Experience Platform: from 9.0, before 10.4 (fixed in 10.4); version 10.4 only
- Sitecore Managed Cloud: affected versions not specified
Published 2025-06-17. Last modified 2026-06-17.