CVE-2022-4979
Published: Jul 25, 2025
Modified: Mar 23, 2026
Description
A cross-site scripting (XSS) vulnerability exists in Sitecore Experience Platform (XP) 7.5 - 10.2 and CMS 7.2 - 7.2 Update-6 that may allow authenticated Sitecore Shell users to be tricked into executing custom JS code. Managed Cloud Standard customers who run the affected Sitecore Experience Platform / CMS versions are also affected.
| Vendor | Product | Versions |
|---|---|---|
Sitecore | Experience Platform | affected 7.5 Initial Release - <= 7.5 Update-2affected 8.0 Initial Release - <= 8.0 Update-7affected 8.1 Initial Release - <= 8.1 Update-3affected 8.2 Initial Release - <= 8.2 Update-7affected 9.0 Initial Release - <= 9.0 Update-2+6 more versions |
Sitecore | Content Mangement System (CMS) | affected 7.2 Initial Release - <= 7.2 Update-6 |
Sitecore | Managed Cloud | affected * |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now