CVE-2025-34510 is a Zip Slip path-traversal vulnerability in Sitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10.0 through 10.4. An authenticated remote attacker can submit a crafted ZIP archive through an HTTP upload request. Path-traversal sequences in archive entry names allow extraction outside the intended destination, resulting in arbitrary file write. An attacker can leverage this write primitive to achieve code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module targeting Sitecore Experience Platform (XP) versions 10.0.0 through 10.4, exploiting CVE-2025-34510 (path traversal leading to remote code execution) and CVE-2025-34509 (hardcoded credentials for the ServicesAPI account). The exploit works by first authenticating with the hardcoded 'ServicesAPI' account, then leveraging a vulnerable file upload endpoint ('/sitecore/shell/Applications/Dialogs/Upload/Upload2.aspx') to perform a Zip Slip attack. This allows the attacker to upload an ASPX webshell to the web root, which is then executed to achieve remote code execution. The module uses Metasploit's command stager to deliver a Windows payload, and is operational with a hardcoded payload, but can be customized within the Metasploit framework. The exploit requires network access to the Sitecore web interface and is post-authentication, relying on the default credentials. The code is well-structured, leverages Metasploit's HTTP and command stager mixins, and provides a reliable method for achieving RCE on vulnerable Sitecore XP installations.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical Sitecore Experience Platform vulnerability covered by SC2025-003 that could lead to remote code execution and unauthorized information access.
A previously disclosed Sitecore deserialization vulnerability referenced alongside other recent Sitecore flaws.
Unknown (listed as a trending CVE; associated in the list with Sitecore Experience Platform, but no technical details provided).
A post-auth remote code execution vulnerability in Sitecore Experience Platform (referenced from prior research) achieved via a path traversal condition leading to code execution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.