Technology · Sitecore
Sitecore CMS vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 61 vulnerabilities in Sitecore CMS: 0 in the last 7 days and 51 in the last 90 days, 7 of them critical and 2 exploited in the wild. The most recent, CVE-2026-92970, was published on 17 September 2026.
- Last 7 days
- 0
- Last 90 days
- 51
- Critical, all time
- 7
- Exploited in the wild
- 2
About Sitecore CMS
A content management system built on the .NET framework for enterprise-level digital experience management.
Latest Sitecore CMS vulnerabilities
- CVE-2026-92970: HUBzero CMS path traversal in project file uploadhighCVSS 8.8EPSS 0.8%
- CVE-2026-92594: Craft CMS GraphQL authorization bypass in draftCreator and revisionCreator fieldshighCVSS 7.5EPSS 0.4%
- CVE-2026-92593: Craft CMS authenticated server-side template injectionhighCVSS 8.8EPSS 0.5%
- CVE-2026-92592: Craft CMS authenticated remote code execution via signed-cookie confusionhighCVSS 8.8EPSS 0.7%
- CVE-2026-92591: Craft CMS environment secrets exposure during database outagemediumCVSS 5.9EPSS 0.4%
- CVE-2026-92590: Craft CMS stored cross-site scripting in Generated FieldsmediumCVSS 5.4EPSS 0.2%
- CVE-2026-92589: Craft CMS broken access control in nested-elements reordermediumCVSS 4.3EPSS 0.3%
- CVE-2026-90709: Yot CMS code injection in Admin Console evalmediumCVSS 4.7EPSS 0.4%
- CVE-2026-90708: Yot CMS SQL injection in cookie auto-login handlerhighCVSS 7.3EPSS 0.4%
- CVE-2026-87930: MaxSite CMS unsafe deserialization of session cookieshighCVSS 8.1EPSS 0.6%
- CVE-2026-87929: MaxSite CMS hardcoded session encryption key auth bypasscriticalCVSS 9.8EPSS 0.5%
- CVE-2026-87928: MaxSite CMS stored cross-site scripting in admin upload handlermediumCVSS 5.4EPSS 0.3%
- CVE-2026-87927: MaxSite CMS local file inclusion via base64 path traversalhighCVSS 8.2EPSS 0.6%
- CVE-2026-86731: Craft CMS missing admin-target guard in user activationmediumCVSS 6.5EPSS 0.3%
- CVE-2026-86730: Craft CMS behavior injection in field-layout elementshighCVSS 8.8EPSS 0.7%
- CVE-2026-86308: light0011 CMS information disclosure in debug modemediumCVSS 5.3EPSS 0.5%
- CVE-2026-86307: light0011 CMS cross-site request forgerymediumCVSS 4.3EPSS 0.2%
- CVE-2026-86306: light0011 CMS improper authentication in cookie handlinghighCVSS 7.3EPSS 0.7%
- CVE-2026-86305: light0011 cms unrestricted file upload in Upload::uploadhighCVSS 7.3EPSS 0.5%
- CVE-2026-85382: light0011 CMS stored cross-site scripting in article contentmediumCVSS 4.3EPSS 0.5%
- CVE-2026-85381: light0011 CMS authorization bypass in Chapter ControllermediumCVSS 5.3EPSS 0.6%
- CVE-2026-85380: light0011 cms server-side request forgery in UEditorhighCVSS 7.3EPSS 0.5%
- CVE-2026-85379: light0011 cms SQL injection in article searchhighCVSS 7.3EPSS 0.4%
- CVE-2026-85378: light0011 cms authorization bypass in Chapter ControllerhighCVSS 7.3EPSS 0.5%
- CVE-2026-79990: Craft CMS GraphQL entry mutation site scope bypassinfoEPSS 0.4%
Most severe Sitecore CMS vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2019-9874: Sitecore CMS and Experience Platform (XP) Deserialization Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2019-9875: Sitecore CMS and Experience Platform (XP) Deserialization Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2026-70553: MaxSite CMS remote code execution in install endpointcriticalCVSS 9.8EPSS 1.3%
- CVE-2026-70552: MaxSite CMS authentication bypass in AJAX dispatchercriticalCVSS 9.8EPSS 0.8%
- CVE-2026-87929: MaxSite CMS hardcoded session encryption key auth bypasscriticalCVSS 9.8EPSS 0.5%
- CVE-2026-84795: Craft CMS privilege escalation via admin flag inheritance in user registrationcriticalCVSS 9.8EPSS 0.5%
- CVE-2026-55791: Craft CMS SSRF and JavaScript injection via Host header poisoningcriticalCVSS 9.2
- CVE-2026-92970: HUBzero CMS path traversal in project file uploadhighCVSS 8.8EPSS 0.8%
- CVE-2026-72778: Craft CMS authenticated remote code execution in element-search conditionhighCVSS 8.8EPSS 0.8%
- CVE-2026-72781: Craft CMS remote code execution via Twig sandbox escapehighCVSS 8.8EPSS 0.8%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 3 | 1 | |
| 6 Jul 2026 | 1 | 0 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 2 | 2 | |
| 10 Aug 2026 | 8 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 2 | 0 | |
| 31 Aug 2026 | 15 | 1 | |
| 7 Sep 2026 | 10 | 1 | |
| 14 Sep 2026 | 9 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/cms.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Sitecore CMS vulnerabilities", https://junglewise.ai/threats/technologies/cms, 26 September 2026.