CVE-2025-34511 is an unrestricted file upload vulnerability in Sitecore PowerShell Extensions, an add-on for Sitecore Experience Manager and Sitecore Experience Platform, through version 7.0. An authenticated remote attacker can submit crafted HTTP requests to upload arbitrary files to the server. Uploading server-executable content can result in remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module targeting Sitecore Experience Platform (XP) versions 10.0.0 through 10.4 on Windows. The exploit leverages two vulnerabilities: CVE-2025-34511 (a file upload vulnerability in the PowerShell extension) and CVE-2025-34509 (hardcoded credentials for the 'ServicesAPI' account). The module authenticates using the hardcoded credentials, checks for the presence of the vulnerable PowerShell extension, and uploads a malicious ASPX webshell to the server. The webshell is then triggered to execute arbitrary code, providing remote code execution as the web server user. The main endpoints targeted are the PowerShellUploadFile2.aspx upload handler and the path to the uploaded webshell. The module is operational and allows for customizable payloads via Metasploit's payload system. The repository structure is typical for a Metasploit exploit module, with all logic contained in a single Ruby file.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical Sitecore Experience Platform vulnerability covered by SC2025-003 that could lead to remote code execution and unauthorized information access.
A previously disclosed Sitecore deserialization vulnerability referenced alongside other recent Sitecore flaws.
Unknown (listed as a trending CVE; associated in the list with Sitecore Experience Platform, but no technical details provided).
A post-auth remote code execution vulnerability in Sitecore Experience Platform (referenced from prior research) involving the Sitecore PowerShell Extension as the execution vector.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.