Vulnerabilities > Sitecore > Experience Platform > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-05-22 CVE-2023-27066 Path Traversal vulnerability in Sitecore Experience Platform
Directory Traversal vulnerability in Site Core Experience Platform 10.2 and earlier allows authenticated remote attackers to download arbitrary files via Urlhandle.
network
low complexity
sitecore CWE-22
6.5
2017-03-19 CVE-2016-8855 Cross-site Scripting vulnerability in Sitecore Experience Platform 8.1
Cross-Site Scripting (XSS) in "/sitecore/client/Applications/List Manager/Taskpages/Contact list" in Sitecore Experience Platform 8.1 rev.
network
sitecore CWE-79
4.3