CVE-2025-34509 Scanner
CVE-2025-34509 Scanner - Hard-Coded Credentials vulnerability in Sitecore Experience Manager (XM) and Experience Platform (XP)
Used 2.1k times · 5.9k assets checked · domain, subdomain, ipv4
Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 011967 PRE, and 10.4 to 10.4.1 rev. 011941 PRE contain a hardcoded user account. Unauthenticated and remote attackers can use this account to access administrative API over HTTP.
CVE-2025-34509 Scanner - Hard-Coded Credentials vulnerability in Sitecore Experience Manager (XM) and Experience Platform (XP)
Used 2.1k times · 5.9k assets checked · domain, subdomain, ipv4
S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.
Create a free account →