HTML Cache Poisoning through Unsafe Reflections
53Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.8epss 14%
from disclosure to weapon0 days
Published on NVDSep 3
1st PoCSep 1
exploitation probability
14%top 4% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Cache Poisoning.This issue affects Sitecore Experience Manager (XM): from 9.0 through 9.3, from 10.0 through 10.4; Experience Platform (XP): from 9.0 through 9.3, from 10.0 through 10.4.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
public PoCs found — 1
githubgithub.com/blueisbeautiful/CVE-2025-53693★ 1⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.