Experience Commerce

by Sitecore

Take action — actively targeted

Experience Commerce is actively targeted by attackers. A significant proportion of its known vulnerabilities are being exploited.

What to do
  1. Apply all available updates immediately
  2. Review your exposure — is this internet-facing?
  3. Monitor vendor advisories for this product

What Attackers Target

Vulnerabilities with high exploit probability 50.0%
Confirmed actively exploited (CISA) 10.0%
Public exploit code available 0.0%
Based on 10 known vulnerabilities. Percentages show the proportion that are actively dangerous — a low percentage means most vulnerabilities in this product are not being exploited.

Most Dangerous Vulnerabilities

CVE CVSS Exploit Probability Confirmed
CVE-2023-35813 9.8 93.5%
CVE-2024-46938 7.5 93.4%
CVE-2025-34510 8.8 86.0%
CVE-2025-34511 8.8 84.6%
CVE-2025-34509 7.5 18.1%
CVE-2025-53690 9.0 8.5% Yes
CVE-2025-53691 8.8 5.0%
CVE-2023-33651 7.5 0.4%
CVE-2025-53693 9.8 0.4%
CVE-2025-53694 7.5 0.1%
50
/ 100
high-risk
Active Threat 47/50 · Critical
Exploit Availability 3/50 · Minimal

Score uses Wilson score intervals to account for sample size. Products with few CVEs are scored conservatively.