References https://nvd.nist.gov/vuln/detail/CVE-2025-27218 https://slcyber.io/research-center/sitecore-unsafe-deserialisation-again-cve-2025-27218/ https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1003535 https://cloud.tencent.com/developer/article/2549757 https://avd.aliyun.com/detail?id=AVD-2025-27218 https://www.exploit-db.com/exploits/52344 https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-27218.yaml https://www.rapid7.com/db/modules/exploit/windows/http/sitecore_xp_cve_2025_27218/ https://cn-sec.com/archives/3980392.html https://www.tenable.com/plugins/was/114649
Related VulnerabilitiesPoCCVE-2021-42237: Sitecore Experience Platform Pre-Auth RCEPoCCVE-2023-35813: Sitecore - Remote Code ExecutionPoCCVE-2024-46938: Sitecore Experience Platform <= 10.4 - Arbitrary File ReadPoCCVE-2025-27218: Sitecore Experience Manager (XM)/Experience Platform (XP) 10.4 - Insecure DeserializationPoCCVE-2014-100004: Sitecore CMS - Cross-Site ScriptingPoCCVE-2019-9874: Sitecore Experience Platform - Deserialization of Untrusted DataPoCsitecore-debug-page: SiteCore Debug PagePoCsitecore-lfi: Sitecore 9.3 - Webroot File ReadPoCCVE-2025-34509: Sitecore Experience Manager (XM) and Experience Platform (XP) - Hardcoded CredentialsSiteCore 文件读取漏洞(CVE-2024-46938)Sitecore Experience Manager和Experience Platform 安全漏洞Sitecore CMS bundle 任意文件读取漏洞