Adobe Connect vulnerabilities
37 known vulnerabilities affecting adobe/adobe_connect.
Total CVEs
37
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH3MEDIUM23
Vulnerabilities
Page 1 of 2
CVE-2026-27243CRITICALCVSS 9.3≤ 12.102026-04-14
CVE-2026-27243 [CRITICAL] CWE-79 CVE-2026-27243: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (X
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Scope is changed.
cvelistv5nvd
CVE-2026-27245CRITICALCVSS 9.3≤ 12.102026-04-14
CVE-2026-27245 [CRITICAL] CWE-79 CVE-2026-27245: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (X
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Scope is changed.
cvelistv5nvd
CVE-2026-27246CRITICALCVSS 9.3≤ 12.102026-04-14
CVE-2026-27246 [CRITICAL] CWE-79 CVE-2026-27246: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (X
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a
cvelistv5nvd
CVE-2026-27303CRITICALCVSS 9.6≤ 12.102026-04-14
CVE-2026-27303 [CRITICAL] CWE-502 CVE-2026-27303: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
cvelistv5nvd
CVE-2026-34615CRITICALCVSS 9.3≤ 12.102026-04-14
CVE-2026-34615 [CRITICAL] CWE-502 CVE-2026-34615: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
cvelistv5nvd
CVE-2026-34617HIGHCVSS 8.7≤ 12.102026-04-14
CVE-2026-34617 [HIGH] CWE-79 CVE-2026-34617: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Cross-Site Scripting (XSS) vulner
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation o
cvelistv5nvd
CVE-2026-21331MEDIUMCVSS 6.1≤ 12.102026-04-14
CVE-2026-21331 [MEDIUM] CWE-79 CVE-2026-21331: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (X
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Scope is changed.
cvelistv5nvd
CVE-2026-34614MEDIUMCVSS 6.1≤ 12.102026-04-14
CVE-2026-34614 [MEDIUM] CWE-79 CVE-2026-34614: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (X
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Scope is changed.
cvelistv5nvd
CVE-2025-49553CRITICALCVSS 9.3≤ 12.92025-10-14
CVE-2025-49553 [CRITICAL] CWE-79 CVE-2025-49553: Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulne
Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute malicious scripts in a victim's browser. Exploitation of this issue requires user interaction in that a victim must navigate to a crafted web page. A successful attacker can abuse this to ach
cvelistv5nvd
CVE-2025-49552HIGHCVSS 8.1≤ 12.92025-10-14
CVE-2025-49552 [HIGH] CWE-79 CVE-2025-49552: Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulne
Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a high-privileged attacker to execute malicious scripts in a victim's browser. Exploitation of this issue requires user interaction in that a victim must navigate to a crafted web page. A successful attacker can abuse
cvelistv5nvd
CVE-2025-54196MEDIUMCVSS 6.1≤ 12.92025-10-14
CVE-2025-54196 [MEDIUM] CWE-601 CVE-2025-54196: Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open R
Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction in that a victim must click on a crafted link.
cvelistv5nvd
CVE-2025-27203CRITICALCVSS 9.6≤ 24.02025-07-08
CVE-2025-27203 [CRITICAL] CWE-502 CVE-2025-27203: Adobe Connect versions 24.0 and earlier are affected by a Deserialization of Untrusted Data vulnerab
Adobe Connect versions 24.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does require user interaction and scope is changed.
cvelistv5nvd
CVE-2025-43567CRITICALCVSS 9.3≤ 12.82025-05-13
CVE-2025-43567 [CRITICAL] CWE-79 CVE-2025-43567: Adobe Connect versions 12.8 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulne
Adobe Connect versions 12.8 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can a
cvelistv5nvd
CVE-2025-30316MEDIUMCVSS 5.4≤ 12.82025-05-13
CVE-2025-30316 [MEDIUM] CWE-79 CVE-2025-30316: Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerab
Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
cvelistv5nvd
CVE-2025-30315MEDIUMCVSS 6.1≤ 12.82025-05-13
CVE-2025-30315 [MEDIUM] CWE-79 CVE-2025-30315: Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerab
Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
cvelistv5nvd
CVE-2025-30314MEDIUMCVSS 6.1≤ 12.82025-05-13
CVE-2025-30314 [MEDIUM] CWE-79 CVE-2025-30314: Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerab
Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
cvelistv5nvd
CVE-2024-54034CRITICALCVSS 9.3≤ 11.4.72024-12-10
CVE-2024-54034 [CRITICAL] CWE-79 CVE-2024-54034: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XS
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. A successful attacker can abuse this to achieve sessi
cvelistv5nvd
CVE-2024-54032CRITICALCVSS 9.3≤ 11.4.72024-12-10
CVE-2024-54032 [CRITICAL] CWE-79 CVE-2024-54032: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS)
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker c
cvelistv5nvd
CVE-2024-54036CRITICALCVSS 9.3≤ 11.4.72024-12-10
CVE-2024-54036 [CRITICAL] CWE-79 CVE-2024-54036: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS)
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker c
cvelistv5nvd
CVE-2024-54037HIGHCVSS 8.1≤ 11.4.72024-12-10
CVE-2024-54037 [HIGH] CWE-79 CVE-2024-54037: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a DOM-based Cross-Site Scripting (XS
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URL or user input, the high-privileged attacker can inject malicious scripts
cvelistv5nvd
1 / 2Next →