CVE-2025-53693: Sitecore Experience Commerce

Critical severity, CVSS 9.8. EPSS: 20.1% chance of exploitation in the next 30 days.

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Cache Poisoning.This issue affects Sitecore Experience Manager (XM): from 9.0 through 9.3, from 10.0 through 10.4; Experience Platform (XP): from 9.0 through 9.3, from 10.0 through 10.4.

Affected products

  • Sitecore Experience Commerce: from 9.0, up to and including 10.4
  • Sitecore Experience Manager: from 9.0, up to and including 10.4
  • Sitecore Experience Platform: from 9.0, before 10.4 (fixed in 10.4); version 10.4 only
  • Sitecore Managed Cloud: affected versions not specified

Published 2025-09-03. Last modified 2026-06-17.