Loading
Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationResult.aspx.
Use CWE-502, Sitecore vendor hub and Experience Platform product page to widen CVE-2023-27068 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-53690, CVE-2025-53693 and CVE-2023-35813 for nearby disclosures in the same product family.