Sitecore PowerShell Extension RCE via Unrestricted Upload
CVSS v3
8.8
HIGH
EPSS Score
85.8%
exploit probability
CISA KEV
No
known exploited
Exploitation
none
SSVC status
Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an unrestricted file upload issue. A remote, authenticated attacker can upload arbitrary files to the server using crafted HTTP requests, resulting in remote code execution.
Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an unrestricted file upload issue. A remote, authenticated attacker can upload arbitrary files to the server using crafted HTTP requests, resulting in remote code execution.
Active exploitation of CVE-2025-34511 has not been confirmed. The EPSS score is 85.8%, indicating the estimated probability of exploitation in the next 30 days.
CVE-2025-34511 has a CVSS v3 base score of 8.8 (HIGH severity), with vector string 3.1.
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
Ranked by exploit probability (EPSS).