CVE-2025-53694: Sitecore Experience Commerce

High severity, CVSS 7.5. EPSS: 6.5% chance of exploitation in the next 30 days.

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP).This issue affects Sitecore Experience Manager (XM): from 9.2 through 10.4; Experience Platform (XP): from 9.2 through 10.4.

Affected products

  • Sitecore Experience Commerce: from 9.2, up to and including 10.4
  • Sitecore Experience Manager: from 9.2, up to and including 10.4
  • Sitecore Experience Platform: from 9.2, before 10.4 (fixed in 10.4); version 10.4 only
  • Sitecore Managed Cloud: affected versions not specified

Published 2025-09-03. Last modified 2026-06-17.