{"schema_version":1,"title":"Sitecore CMS vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 61 vulnerabilities in Sitecore CMS: 0 in the last 7 days and 51 in the last 90 days, 7 of them critical and 2 exploited in the wild. The most recent, CVE-2026-92970, was published on 17 September 2026.","url":"https://junglewise.ai/threats/technologies/cms","json_url":"https://junglewise.ai/threats/technologies/cms.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/cms","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":21,"all_time":61,"critical":7,"exploited":2,"last_7_days":0,"last_30_days":35,"last_90_days":51,"last_365_days":56},"latest":[{"cve":"CVE-2026-92970","cvss":8.8,"epss":0.0082,"slug":"cve-2026-92970-hubzero-cms-path-traversal-in-project-file-upload","title":"HUBzero CMS path traversal in project file upload","severity":"high","exploited":false,"published_at":"2026-09-17T14:18:02.997+00:00","url":"https://junglewise.ai/threats/cve-2026-92970-hubzero-cms-path-traversal-in-project-file-upload"},{"cve":"CVE-2026-92594","cvss":7.5,"epss":0.0043,"slug":"cve-2026-92594-craft-cms-graphql-authorization-bypass-in-draftcreator-and","title":"Craft CMS GraphQL authorization bypass in draftCreator and revisionCreator fields","severity":"high","exploited":false,"published_at":"2026-09-16T22:18:30.283+00:00","url":"https://junglewise.ai/threats/cve-2026-92594-craft-cms-graphql-authorization-bypass-in-draftcreator-and"},{"cve":"CVE-2026-92593","cvss":8.8,"epss":0.0055,"slug":"cve-2026-92593-craft-cms-authenticated-server-side-template-injection","title":"Craft CMS authenticated server-side template injection","severity":"high","exploited":false,"published_at":"2026-09-16T22:18:30.15+00:00","url":"https://junglewise.ai/threats/cve-2026-92593-craft-cms-authenticated-server-side-template-injection"},{"cve":"CVE-2026-92592","cvss":8.8,"epss":0.0065,"slug":"cve-2026-92592-craft-cms-authenticated-remote-code-execution-via-signed-cookie","title":"Craft CMS authenticated remote code execution via signed-cookie confusion","severity":"high","exploited":false,"published_at":"2026-09-16T22:18:30.013+00:00","url":"https://junglewise.ai/threats/cve-2026-92592-craft-cms-authenticated-remote-code-execution-via-signed-cookie"},{"cve":"CVE-2026-92591","cvss":5.9,"epss":0.0041,"slug":"cve-2026-92591-craft-cms-environment-secrets-exposure-during-database-outage","title":"Craft CMS environment secrets exposure during database outage","severity":"medium","exploited":false,"published_at":"2026-09-16T22:18:29.873+00:00","url":"https://junglewise.ai/threats/cve-2026-92591-craft-cms-environment-secrets-exposure-during-database-outage"},{"cve":"CVE-2026-92590","cvss":5.4,"epss":0.0024,"slug":"cve-2026-92590-craft-cms-stored-cross-site-scripting-in-generated-fields","title":"Craft CMS stored cross-site scripting in Generated Fields","severity":"medium","exploited":false,"published_at":"2026-09-16T22:18:29.73+00:00","url":"https://junglewise.ai/threats/cve-2026-92590-craft-cms-stored-cross-site-scripting-in-generated-fields"},{"cve":"CVE-2026-92589","cvss":4.3,"epss":0.0026,"slug":"cve-2026-92589-craft-cms-broken-access-control-in-nested-elements-reorder","title":"Craft CMS broken access control in nested-elements reorder","severity":"medium","exploited":false,"published_at":"2026-09-16T22:18:29.583+00:00","url":"https://junglewise.ai/threats/cve-2026-92589-craft-cms-broken-access-control-in-nested-elements-reorder"},{"cve":"CVE-2026-90709","cvss":4.7,"epss":0.0041,"slug":"cve-2026-90709-yot-cms-code-injection-in-admin-console-eval","title":"Yot CMS code injection in Admin Console eval","severity":"medium","exploited":false,"published_at":"2026-09-14T12:17:50.83+00:00","url":"https://junglewise.ai/threats/cve-2026-90709-yot-cms-code-injection-in-admin-console-eval"},{"cve":"CVE-2026-90708","cvss":7.3,"epss":0.0041,"slug":"cve-2026-90708-yot-cms-sql-injection-in-cookie-auto-login-handler","title":"Yot CMS SQL injection in cookie auto-login handler","severity":"high","exploited":false,"published_at":"2026-09-14T11:17:07.313+00:00","url":"https://junglewise.ai/threats/cve-2026-90708-yot-cms-sql-injection-in-cookie-auto-login-handler"},{"cve":"CVE-2026-87930","cvss":8.1,"epss":0.0061,"slug":"cve-2026-87930-maxsite-cms-unsafe-deserialization-of-session-cookies","title":"MaxSite CMS unsafe deserialization of session cookies","severity":"high","exploited":false,"published_at":"2026-09-09T17:17:53.99+00:00","url":"https://junglewise.ai/threats/cve-2026-87930-maxsite-cms-unsafe-deserialization-of-session-cookies"},{"cve":"CVE-2026-87929","cvss":9.8,"epss":0.0053,"slug":"cve-2026-87929-maxsite-cms-hardcoded-session-encryption-key-auth-bypass","title":"MaxSite CMS hardcoded session encryption key auth bypass","severity":"critical","exploited":false,"published_at":"2026-09-09T17:17:53.84+00:00","url":"https://junglewise.ai/threats/cve-2026-87929-maxsite-cms-hardcoded-session-encryption-key-auth-bypass"},{"cve":"CVE-2026-87928","cvss":5.4,"epss":0.003,"slug":"cve-2026-87928-maxsite-cms-stored-cross-site-scripting-in-admin-upload-handler","title":"MaxSite CMS stored cross-site scripting in admin upload handler","severity":"medium","exploited":false,"published_at":"2026-09-09T17:17:53.697+00:00","url":"https://junglewise.ai/threats/cve-2026-87928-maxsite-cms-stored-cross-site-scripting-in-admin-upload-handler"},{"cve":"CVE-2026-87927","cvss":8.2,"epss":0.0059,"slug":"cve-2026-87927-maxsite-cms-local-file-inclusion-via-base64-path-traversal","title":"MaxSite CMS local file inclusion via base64 path traversal","severity":"high","exploited":false,"published_at":"2026-09-09T17:17:53.52+00:00","url":"https://junglewise.ai/threats/cve-2026-87927-maxsite-cms-local-file-inclusion-via-base64-path-traversal"},{"cve":"CVE-2026-86731","cvss":6.5,"epss":0.0031,"slug":"cve-2026-86731-craft-cms-missing-admin-target-guard-in-user-activation","title":"Craft CMS missing admin-target guard in user activation","severity":"medium","exploited":false,"published_at":"2026-09-08T16:18:35.187+00:00","url":"https://junglewise.ai/threats/cve-2026-86731-craft-cms-missing-admin-target-guard-in-user-activation"},{"cve":"CVE-2026-86730","cvss":8.8,"epss":0.0071,"slug":"cve-2026-86730-craft-cms-behavior-injection-in-field-layout-elements","title":"Craft CMS behavior injection in field-layout elements","severity":"high","exploited":false,"published_at":"2026-09-08T16:18:34.667+00:00","url":"https://junglewise.ai/threats/cve-2026-86730-craft-cms-behavior-injection-in-field-layout-elements"},{"cve":"CVE-2026-86308","cvss":5.3,"epss":0.0054,"slug":"cve-2026-86308-light0011-cms-information-disclosure-in-debug-mode","title":"light0011 CMS information disclosure in debug mode","severity":"medium","exploited":false,"published_at":"2026-09-07T14:16:56.12+00:00","url":"https://junglewise.ai/threats/cve-2026-86308-light0011-cms-information-disclosure-in-debug-mode"},{"cve":"CVE-2026-86307","cvss":4.3,"epss":0.0023,"slug":"cve-2026-86307-light0011-cms-cross-site-request-forgery","title":"light0011 CMS cross-site request forgery","severity":"medium","exploited":false,"published_at":"2026-09-07T14:16:55.927+00:00","url":"https://junglewise.ai/threats/cve-2026-86307-light0011-cms-cross-site-request-forgery"},{"cve":"CVE-2026-86306","cvss":7.3,"epss":0.0069,"slug":"cve-2026-86306-light0011-cms-improper-authentication-in-cookie-handling","title":"light0011 CMS improper authentication in cookie handling","severity":"high","exploited":false,"published_at":"2026-09-07T13:20:39.927+00:00","url":"https://junglewise.ai/threats/cve-2026-86306-light0011-cms-improper-authentication-in-cookie-handling"},{"cve":"CVE-2026-86305","cvss":7.3,"epss":0.005,"slug":"cve-2026-86305-light0011-cms-unrestricted-file-upload-in-upload-upload","title":"light0011 cms unrestricted file upload in Upload::upload","severity":"high","exploited":false,"published_at":"2026-09-07T13:20:39.753+00:00","url":"https://junglewise.ai/threats/cve-2026-86305-light0011-cms-unrestricted-file-upload-in-upload-upload"},{"cve":"CVE-2026-85382","cvss":4.3,"epss":0.0047,"slug":"cve-2026-85382-light0011-cms-stored-cross-site-scripting-in-article-content","title":"light0011 CMS stored cross-site scripting in article content","severity":"medium","exploited":false,"published_at":"2026-09-04T02:17:20.017+00:00","url":"https://junglewise.ai/threats/cve-2026-85382-light0011-cms-stored-cross-site-scripting-in-article-content"},{"cve":"CVE-2026-85381","cvss":5.3,"epss":0.0057,"slug":"cve-2026-85381-light0011-cms-authorization-bypass-in-chapter-controller","title":"light0011 CMS authorization bypass in Chapter Controller","severity":"medium","exploited":false,"published_at":"2026-09-04T01:17:22.883+00:00","url":"https://junglewise.ai/threats/cve-2026-85381-light0011-cms-authorization-bypass-in-chapter-controller"},{"cve":"CVE-2026-85380","cvss":7.3,"epss":0.005,"slug":"cve-2026-85380-light0011-cms-server-side-request-forgery-in-ueditor","title":"light0011 cms server-side request forgery in UEditor","severity":"high","exploited":false,"published_at":"2026-09-04T01:17:22.71+00:00","url":"https://junglewise.ai/threats/cve-2026-85380-light0011-cms-server-side-request-forgery-in-ueditor"},{"cve":"CVE-2026-85379","cvss":7.3,"epss":0.0043,"slug":"cve-2026-85379-light0011-cms-sql-injection-in-article-search","title":"light0011 cms SQL injection in article search","severity":"high","exploited":false,"published_at":"2026-09-04T01:17:22.537+00:00","url":"https://junglewise.ai/threats/cve-2026-85379-light0011-cms-sql-injection-in-article-search"},{"cve":"CVE-2026-85378","cvss":7.3,"epss":0.0052,"slug":"cve-2026-85378-light0011-cms-authorization-bypass-in-chapter-controller","title":"light0011 cms authorization bypass in Chapter Controller","severity":"high","exploited":false,"published_at":"2026-09-03T23:17:20.987+00:00","url":"https://junglewise.ai/threats/cve-2026-85378-light0011-cms-authorization-bypass-in-chapter-controller"},{"cve":"CVE-2026-79990","epss":0.0045,"slug":"cve-2026-79990-craft-cms-graphql-entry-mutation-site-scope-bypass","title":"Craft CMS GraphQL entry mutation site scope bypass","severity":"info","exploited":false,"published_at":"2026-09-02T15:17:42.473+00:00","url":"https://junglewise.ai/threats/cve-2026-79990-craft-cms-graphql-entry-mutation-site-scope-bypass"}],"weekly":[{"week":"2026-06-29","critical":1,"exploited":0,"vulnerabilities":3},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":2,"exploited":0,"vulnerabilities":2},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":8},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-31","critical":1,"exploited":0,"vulnerabilities":15},{"week":"2026-09-07","critical":1,"exploited":0,"vulnerabilities":10},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":9},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Sitecore Experience Platform (XP)","slug":"experience-platform-xp","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/experience-platform-xp"}],"technology":{"hub":true,"name":"Sitecore CMS","slug":"cms","vendor":{"name":"Sitecore","slug":"sitecore","url":"https://junglewise.ai/threats/vendors/sitecore"},"aliases":[],"homepage":"https://www.sitecore.com/products/content-hub","description":"A content management system built on the .NET framework for enterprise-level digital experience management.","url":"https://junglewise.ai/threats/technologies/cms"},"most_severe":[{"cve":"CVE-2019-9874","cvss":9.8,"slug":"cve-2019-9874-sitecore-cms-and-experience-platform-xp-deserialization","title":"Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability","severity":"critical","exploited":true,"published_at":"2025-03-26T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2019-9874-sitecore-cms-and-experience-platform-xp-deserialization"},{"cve":"CVE-2019-9875","cvss":8.8,"slug":"cve-2019-9875-sitecore-cms-and-experience-platform-xp-deserialization","title":"Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability","severity":"critical","exploited":true,"published_at":"2025-03-26T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2019-9875-sitecore-cms-and-experience-platform-xp-deserialization"},{"cve":"CVE-2026-70553","cvss":9.8,"epss":0.0127,"slug":"cve-2026-70553-maxsite-cms-remote-code-execution-in-install-endpoint","title":"MaxSite CMS remote code execution in install endpoint","severity":"critical","exploited":false,"published_at":"2026-08-04T20:16:56.023+00:00","url":"https://junglewise.ai/threats/cve-2026-70553-maxsite-cms-remote-code-execution-in-install-endpoint"},{"cve":"CVE-2026-70552","cvss":9.8,"epss":0.0083,"slug":"cve-2026-70552-maxsite-cms-authentication-bypass-in-ajax-dispatcher","title":"MaxSite CMS authentication bypass in AJAX dispatcher","severity":"critical","exploited":false,"published_at":"2026-08-04T20:16:55.883+00:00","url":"https://junglewise.ai/threats/cve-2026-70552-maxsite-cms-authentication-bypass-in-ajax-dispatcher"},{"cve":"CVE-2026-87929","cvss":9.8,"epss":0.0053,"slug":"cve-2026-87929-maxsite-cms-hardcoded-session-encryption-key-auth-bypass","title":"MaxSite CMS hardcoded session encryption key auth bypass","severity":"critical","exploited":false,"published_at":"2026-09-09T17:17:53.84+00:00","url":"https://junglewise.ai/threats/cve-2026-87929-maxsite-cms-hardcoded-session-encryption-key-auth-bypass"},{"cve":"CVE-2026-84795","cvss":9.8,"epss":0.0051,"slug":"cve-2026-84795-craft-cms-privilege-escalation-via-admin-flag-inheritance-in-user","title":"Craft CMS privilege escalation via admin flag inheritance in user registration","severity":"critical","exploited":false,"published_at":"2026-09-02T12:17:16.093+00:00","url":"https://junglewise.ai/threats/cve-2026-84795-craft-cms-privilege-escalation-via-admin-flag-inheritance-in-user"},{"cve":"CVE-2026-55791","cvss":9.2,"slug":"cve-2026-55791-craft-cms-ssrf-and-javascript-injection-via-host-header-poisoning","title":"Craft CMS SSRF and JavaScript injection via Host header poisoning","severity":"critical","exploited":false,"published_at":"2026-07-02T00:16:44.803+00:00","url":"https://junglewise.ai/threats/cve-2026-55791-craft-cms-ssrf-and-javascript-injection-via-host-header-poisoning"},{"cve":"CVE-2026-92970","cvss":8.8,"epss":0.0082,"slug":"cve-2026-92970-hubzero-cms-path-traversal-in-project-file-upload","title":"HUBzero CMS path traversal in project file upload","severity":"high","exploited":false,"published_at":"2026-09-17T14:18:02.997+00:00","url":"https://junglewise.ai/threats/cve-2026-92970-hubzero-cms-path-traversal-in-project-file-upload"},{"cve":"CVE-2026-72778","cvss":8.8,"epss":0.008,"slug":"cve-2026-72778-craft-cms-authenticated-remote-code-execution-in-element-search","title":"Craft CMS authenticated remote code execution in element-search condition","severity":"high","exploited":false,"published_at":"2026-08-11T13:19:08.207+00:00","url":"https://junglewise.ai/threats/cve-2026-72778-craft-cms-authenticated-remote-code-execution-in-element-search"},{"cve":"CVE-2026-72781","cvss":8.8,"epss":0.0079,"slug":"cve-2026-72781-craft-cms-remote-code-execution-via-twig-sandbox-escape","title":"Craft CMS remote code execution via Twig sandbox escape","severity":"high","exploited":false,"published_at":"2026-08-11T13:19:08.657+00:00","url":"https://junglewise.ai/threats/cve-2026-72781-craft-cms-remote-code-execution-via-twig-sandbox-escape"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}