CVE-2025-34511: Sitecore Experience Commerce

High severity, CVSS 8.8. EPSS: 29.8% chance of exploitation in the next 30 days.

Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an unrestricted file upload issue. A remote, authenticated attacker can upload arbitrary files to the server using crafted HTTP requests, resulting in remote code execution.

Affected products

  • Sitecore Experience Commerce: from 9.0, up to and including 10.4
  • Sitecore Experience Manager: from 9.0, up to and including 10.4
  • Sitecore Experience Platform: from 9.0, before 10.4 (fixed in 10.4); version 10.4 only
  • Sitecore Managed Cloud: affected versions not specified

Published 2025-06-17. Last modified 2026-06-17.