Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-55211 | A cross-site scripting (XSS) vulnerability exists in Sitecore Experience Platform (XP) 7.5 - 10.2 and CMS 7.2 - 7.2 Update-6 that may allow authenticated Sitecore Shell users to be tricked into executing custom JS code. Managed Cloud Standard customers who run the affected Sitecore Experience Platform / CMS versions are also affected. |
Fri, 21 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:sitecore:cms:7.2:*:*:*:*:*:*:* cpe:2.3:a:sitecore:experience_platform:10.1:*:*:*:*:*:*:* cpe:2.3:a:sitecore:experience_platform:10.2:*:*:*:*:*:*:* cpe:2.3:a:sitecore:experience_platform:10:*:*:*:*:*:*:* cpe:2.3:a:sitecore:experience_platform:7.5:*:*:*:*:*:*:* cpe:2.3:a:sitecore:experience_platform:8.0:*:*:*:*:*:*:* cpe:2.3:a:sitecore:experience_platform:8.1:*:*:*:*:*:*:* cpe:2.3:a:sitecore:experience_platform:8.2:*:*:*:*:*:*:* cpe:2.3:a:sitecore:experience_platform:9.0:*:*:*:*:*:*:* cpe:2.3:a:sitecore:experience_platform:9.1:*:*:*:*:*:*:* cpe:2.3:a:sitecore:experience_platform:9.2:*:*:*:*:*:*:* cpe:2.3:a:sitecore:experience_platform:9.3:*:*:*:*:*:*:* cpe:2.3:a:sitecore:managed_cloud:-:*:*:*:*:*:*:* |
Thu, 31 Jul 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sitecore
Sitecore cms Sitecore experience Platform Sitecore managed Cloud Sitecore sitecore |
|
| Vendors & Products |
Sitecore
Sitecore cms Sitecore experience Platform Sitecore managed Cloud Sitecore sitecore |
Fri, 25 Jul 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 25 Jul 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A cross-site scripting (XSS) vulnerability exists in Sitecore Experience Platform (XP) 7.5 - 10.2 and CMS 7.2 - 7.2 Update-6 that may allow authenticated Sitecore Shell users to be tricked into executing custom JS code. Managed Cloud Standard customers who run the affected Sitecore Experience Platform / CMS versions are also affected. | |
| Title | Sitecore XP 7.5 - 10.2, CMS 7.2, and Managed Cloud XSS | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-23T15:43:29.702Z
Reserved: 2025-07-24T15:19:26.600Z
Link: CVE-2022-4979
Updated: 2025-07-25T17:39:53.725Z
Status : Deferred
Published: 2025-07-25T16:15:27.230
Modified: 2026-04-15T00:35:42.020
Link: CVE-2022-4979
No data.
OpenCVE Enrichment
Updated: 2025-07-31T10:21:32Z
EUVD