CVE-2025-53694 is an information disclosure vulnerability in Sitecore Experience Manager (XM) and Sitecore Experience Platform (XP) affecting versions 9.2 through 10.4. According to the provided content, the issue is in the ItemService API search functionality, where a mismatch exists between authorization filtering and result counting. Specifically, TotalCount is calculated from unfiltered Apache Solr search results, while the returned item list is filtered according to access controls. As a result, an unauthorized or anonymous actor can issue search queries, including wildcard-style queries, and infer the existence of restricted items even when those items are not returned in the response. This enables blind enumeration of content and metadata in environments where the ItemService search endpoint is reachable.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a comprehensive proof-of-concept exploit chain targeting three critical vulnerabilities in Sitecore Experience Platform (XP) up to version 10.4.1: CVE-2025-53694 (information disclosure), CVE-2025-53693 (cache poisoning), and CVE-2025-53691 (remote code execution via deserialization). The main exploit logic resides in 'chain.py', a Python script that automates the full attack sequence: it first leverages the ItemService API to enumerate internal Sitecore data, then abuses the XAML handler to poison the application cache, and finally exploits insecure deserialization in the AjaxScriptManager to achieve unauthenticated RCE. The repository also includes a Nuclei detection template ('sitecore.yaml') for automated vulnerability scanning, a detailed technical report ('REPORT.md'), and search dorks ('dorks.md') for identifying potential targets. The exploit is operational, requiring only a target URL and a command to execute. The attack is performed entirely over HTTP(S) endpoints exposed by vulnerable Sitecore instances, with no authentication required. The code is well-structured, modular, and provides clear output for each attack stage. This repository is a high-quality resource for both offensive security research and defensive mitigation planning.
This repository contains a Python exploit script (exploit.py) targeting CVE-2025-53694, an information disclosure vulnerability in the Sitecore Experience Platform. The exploit abuses the ItemService API endpoint (/sitecore/shell/api/sitecore/ItemService/GetChildren), which is accessible to unauthenticated users, to enumerate internal Sitecore items by brute-forcing common GUIDs and database names (master, web, core). The script checks for vulnerability, enumerates items, and analyzes the results for sensitive information such as credentials, configuration data, file paths, database information, and user data. The repository also includes a README.md with a detailed description of the vulnerability and mitigation advice, and a LICENSE file. The exploit is operational and provides actionable results if the target is vulnerable, but does not include a weaponized or post-exploitation payload.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Sitecore Experience Platform vulnerability mentioned as part of an exploit chain; details not provided in the content snippet.
An additional 2025 Sitecore vulnerability mentioned in a list of recent critical issues, without further detail in the content.
An information disclosure/enumeration issue in Sitecore ItemService (ItemServices API) search behavior where result counts can leak existence of items even when the requesting (restricted/anonymous) user cannot view them, enabling blind-style enumeration (e.g., via wildcard queries) of item identifiers/metadata that can support follow-on attacks like cache-key discovery.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.