Vulnerabilities > Sitecore > Experience Commerce

DATE CVE VULNERABILITY TITLE RISK
2023-06-17 CVE-2023-35813 Unspecified vulnerability in Sitecore products
Multiple Sitecore products allow remote code execution.
network
low complexity
sitecore
critical
9.8
2023-06-06 CVE-2023-33651 Incorrect Authorization vulnerability in Sitecore products
An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initial Release to v13.0 Initial Release allows attackers to bypass authorization rules.
network
low complexity
sitecore CWE-863
7.5