Adobe Experience Manager vulnerabilities
1,019 known vulnerabilities affecting adobe/adobe_experience_manager.
Total CVEs
1,019
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL8HIGH14MEDIUM987LOW10
Vulnerabilities
Page 1 of 51
CVE-2025-54253P1CRITICALCVSS 10.0KEV≤ 6.5.232025-08-05
CVE-2025-54253 [CRITICAL] CWE-863 CVE-2025-54253: Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerabilit
Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.
nvd
CVE-2025-54254P1HIGHCVSS 8.6ExploitedPoC≤ 6.5.232025-08-05
CVE-2025-54254 [HIGH] CWE-611 CVE-2025-54254: Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML
Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the local file system, scope is changed. Exploitation of this issue does not require
nvd
CVE-2025-49533P1CRITICALCVSS 9.8ExploitedPoC≤ 6.5.23.02025-07-08
CVE-2025-49533 [CRITICAL] CWE-502 CVE-2025-49533: Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Unt
Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction. Scope is unchanged.
nvd
CVE-2025-54249P1MEDIUMCVSS 6.5ExploitedPoC≤ 6.5.23.02025-09-09
CVE-2025-54249 [MEDIUM] CWE-918 CVE-2025-54249: Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a Server-Side Request Forgery
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to manipulate server-side requests and bypass security controls allowing unauthorized read access.
nvd
CVE-2025-54251P2MEDIUMCVSS 4.3ExploitedPoC≤ 6.5.23.02025-09-09
CVE-2025-54251 [MEDIUM] CWE-91 CVE-2025-54251: Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an XML Injection vulnerabilit
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an XML Injection vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to manipulate XML queries and gain limited unauthorized write access.
nvd
CVE-2019-8086P2HIGHCVSS 7.5PoCv6.5v6.4+2 more2019-10-25
CVE-2019-8086 [HIGH] CWE-611 CVE-2019-8086: Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnera
Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
nvd
CVE-2019-16469P2HIGHCVSS 7.5PoCv6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 versions2020-01-15
CVE-2019-16469 [HIGH] CWE-917 CVE-2019-16469: Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an expression language injec
Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an expression language injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
nvd
CVE-2019-7964P2CRITICALCVSS 9.8v6.5, and 6.4 versions2019-08-16
CVE-2019-7964 [CRITICAL] CVE-2019-7964: Adobe Experience Manager versions 6.5, and 6.4 have an authentication bypass vulnerability. Successf
Adobe Experience Manager versions 6.5, and 6.4 have an authentication bypass vulnerability. Successful exploitation could lead to remote code execution.
nvd
CVE-2024-26029P3CRITICALCVSS 9.8≤ 6.5.202024-06-13
CVE-2024-26029 [CRITICAL] CWE-284 CVE-2024-26029: Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Access Control vuln
Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain disclose information. Exploitation of this issue does not require user interaction.
nvd
CVE-2019-8088P3CRITICALCVSS 9.8v6.5, 6.4, 6.3, 6.22019-10-25
CVE-2019-8088 [CRITICAL] CWE-77 CVE-2019-8088: Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Succ
Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2025-54248P3HIGHCVSS 7.7≤ 6.5.23.02025-09-09
CVE-2025-54248 [HIGH] CWE-20 CVE-2025-54248: Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Scope is changed
nvd
CVE-2025-46840P3HIGHCVSS 8.7≤ 6.5.222025-06-10
CVE-2025-46840 [HIGH] CWE-285 CVE-2025-46840: Adobe Experience Manager versions 6.5.22 and earlier are affected by an Improper Authorization vulne
Adobe Experience Manager versions 6.5.22 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. A low privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue requires user interaction. A successful attacker can abu
nvd
CVE-2025-64537P3CRITICALCVSS 9.3≤ 6.5.232025-12-10
CVE-2025-64537 [CRITICAL] CWE-79 CVE-2025-64537: Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scriptin
Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by injecting malicious scripts into a web page that are executed in the context of the victim's browser. A successful attacker can abuse t
nvd
CVE-2025-64538P3CRITICALCVSS 9.3≤ 6.5.232025-12-10
CVE-2025-64538 [CRITICAL] CWE-79 CVE-2025-64538: Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scriptin
Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by injecting malicious scripts into a web page that are executed in the context of the victim's browser. A successful attacker can abuse t
nvd
CVE-2025-64539P3CRITICALCVSS 9.3≤ 6.5.232025-12-10
CVE-2025-64539 [CRITICAL] CWE-79 CVE-2025-64539: Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scriptin
Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by injecting malicious scripts into a web page that are executed in the context of the victim's browser. A successful attacker can abuse t
nvd
CVE-2025-46837P3HIGHCVSS 8.7≤ 6.5.222025-06-10
CVE-2025-46837 [HIGH] CWE-79 CVE-2025-46837: Adobe Experience Manager versions 6.5.22 and earlier are affected by a reflected Cross-Site Scriptin
Adobe Experience Manager versions 6.5.22 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A su
nvd
CVE-2019-8087P3HIGHCVSS 7.5v6.5, 6.4, 6.3, 6.22019-10-25
CVE-2019-8087 [HIGH] CWE-611 CVE-2019-8087: Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnera
Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
nvd
CVE-2019-8081P3HIGHCVSS 7.5v6.5, 6.4, 6.3, 6.22019-10-25
CVE-2019-8081 [HIGH] CVE-2019-8081: Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have an authentication bypass vulnerability.
Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have an authentication bypass vulnerability. Successful exploitation could lead to sensitive information disclosure.
nvd
CVE-2019-8082P3HIGHCVSS 7.5v6.4, 6.3, 6.22019-10-25
CVE-2019-8082 [HIGH] CWE-611 CVE-2019-8082: Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a xml external entity injection vulnerabilit
Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
nvd
CVE-2025-54247P3MEDIUMCVSS 6.5≤ 6.5.23.02025-09-09
CVE-2025-54247 [MEDIUM] CWE-20 CVE-2025-54247: Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access.
nvd
1 / 51Next →