Adobe Connect vulnerabilities

29 known vulnerabilities affecting adobe/adobe_connect.

Total CVEs
29
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH2MEDIUM21

Vulnerabilities

Page 1 of 2
CVE-2025-49553CRITICALCVSS 9.3≤ 12.92025-10-14
CVE-2025-49553 [CRITICAL] CWE-79 CVE-2025-49553: Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulne Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute malicious scripts in a victim's browser. Exploitation of this issue requires user interaction in that a victim must navigate to a crafted web page. A successful attacker can abuse this to ach
cvelistv5nvd
CVE-2025-49552HIGHCVSS 8.1≤ 12.92025-10-14
CVE-2025-49552 [HIGH] CWE-79 CVE-2025-49552: Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulne Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a high-privileged attacker to execute malicious scripts in a victim's browser. Exploitation of this issue requires user interaction in that a victim must navigate to a crafted web page. A successful attacker can abuse
cvelistv5nvd
CVE-2025-54196MEDIUMCVSS 6.1≤ 12.92025-10-14
CVE-2025-54196 [LOW] CWE-601 CVE-2025-54196: Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open R Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction in that a victim must click on a crafted link.
cvelistv5nvd
CVE-2025-27203CRITICALCVSS 9.6≤ 24.02025-07-08
CVE-2025-27203 [CRITICAL] CWE-502 CVE-2025-27203: Adobe Connect versions 24.0 and earlier are affected by a Deserialization of Untrusted Data vulnerab Adobe Connect versions 24.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does require user interaction and scope is changed.
cvelistv5nvd
CVE-2025-43567CRITICALCVSS 9.3≤ 12.82025-05-13
CVE-2025-43567 [CRITICAL] CWE-79 CVE-2025-43567: Adobe Connect versions 12.8 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulne Adobe Connect versions 12.8 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can a
cvelistv5nvd
CVE-2025-30316MEDIUMCVSS 5.4≤ 12.82025-05-13
CVE-2025-30316 [MEDIUM] CWE-79 CVE-2025-30316: Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerab Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
cvelistv5nvd
CVE-2025-30315MEDIUMCVSS 6.1≤ 12.82025-05-13
CVE-2025-30315 [MEDIUM] CWE-79 CVE-2025-30315: Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerab Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
cvelistv5nvd
CVE-2025-30314MEDIUMCVSS 6.1≤ 12.82025-05-13
CVE-2025-30314 [MEDIUM] CWE-79 CVE-2025-30314: Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerab Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
cvelistv5nvd
CVE-2024-54034CRITICALCVSS 9.3≤ 11.4.72024-12-10
CVE-2024-54034 [CRITICAL] CWE-79 CVE-2024-54034: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XS Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. A successful attacker can abuse this to achieve sessi
cvelistv5nvd
CVE-2024-54032CRITICALCVSS 9.3≤ 11.4.72024-12-10
CVE-2024-54032 [CRITICAL] CWE-79 CVE-2024-54032: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker c
cvelistv5nvd
CVE-2024-54036CRITICALCVSS 9.3≤ 11.4.72024-12-10
CVE-2024-54036 [CRITICAL] CWE-79 CVE-2024-54036: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker c
cvelistv5nvd
CVE-2024-54037HIGHCVSS 8.1≤ 11.4.72024-12-10
CVE-2024-54037 [HIGH] CWE-79 CVE-2024-54037: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a DOM-based Cross-Site Scripting (XS Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URL or user input, the high-privileged attacker can inject malicious scripts
cvelistv5nvd
CVE-2024-54047MEDIUMCVSS 6.1≤ 11.4.72024-12-10
CVE-2024-54047 [MEDIUM] CWE-79 CVE-2024-54047: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XS Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
cvelistv5nvd
CVE-2024-54040MEDIUMCVSS 5.4≤ 11.4.72024-12-10
CVE-2024-54040 [MEDIUM] CWE-79 CVE-2024-54040: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
cvelistv5nvd
CVE-2024-54039MEDIUMCVSS 5.4≤ 11.4.72024-12-10
CVE-2024-54039 [MEDIUM] CWE-79 CVE-2024-54039: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
cvelistv5nvd
CVE-2024-54042MEDIUMCVSS 6.1≤ 11.4.72024-12-10
CVE-2024-54042 [MEDIUM] CWE-79 CVE-2024-54042: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XS Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
cvelistv5nvd
CVE-2024-54041MEDIUMCVSS 5.4≤ 11.4.72024-12-10
CVE-2024-54041 [MEDIUM] CWE-79 CVE-2024-54041: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
cvelistv5nvd
CVE-2024-49550MEDIUMCVSS 6.1≤ 11.4.72024-12-10
CVE-2024-49550 [MEDIUM] CWE-79 CVE-2024-49550: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XS Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
cvelistv5nvd
CVE-2024-54049MEDIUMCVSS 6.1≤ 11.4.72024-12-10
CVE-2024-54049 [MEDIUM] CWE-79 CVE-2024-54049: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XS Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
cvelistv5nvd
CVE-2024-54048MEDIUMCVSS 6.1≤ 11.4.72024-12-10
CVE-2024-54048 [MEDIUM] CWE-79 CVE-2024-54048: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XS Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
cvelistv5nvd