Vulnerabilities > Sitecore > Experience Commerce > High

DATE CVE VULNERABILITY TITLE RISK
2023-06-06 CVE-2023-33651 Incorrect Authorization vulnerability in Sitecore products
An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initial Release to v13.0 Initial Release allows attackers to bypass authorization rules.
network
low complexity
sitecore CWE-863
7.5