Adobe Experience Manager vulnerabilities
1,019 known vulnerabilities affecting adobe/adobe_experience_manager.
Total CVEs
1,019
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL8HIGH14MEDIUM987LOW10
Vulnerabilities
Page 11 of 51
CVE-2026-27257P4MEDIUMCVSS 5.4≤ 6.5.232026-03-11
CVE-2026-27257 [MEDIUM] CWE-79 CVE-2026-27257: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27242P4MEDIUMCVSS 5.4≤ 6.5.232026-03-11
CVE-2026-27242 [MEDIUM] CWE-79 CVE-2026-27242: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2019-8080P4MEDIUMCVSS 6.1v6.4, 6.32019-10-24
CVE-2019-8080 [MEDIUM] CWE-79 CVE-2019-8080: Adobe Experience Manager versions 6.4 and 6.3 have a stored cross site scripting vulnerability. Succ
Adobe Experience Manager versions 6.4 and 6.3 have a stored cross site scripting vulnerability. Successful exploitation could lead to privilege escalation.
nvd
CVE-2024-36141P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36141 [MEDIUM] CWE-79 CVE-2024-36141: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26092P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-26092 [MEDIUM] CWE-79 CVE-2024-26092: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26054P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-26054 [MEDIUM] CWE-79 CVE-2024-26054: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26081P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-26081 [MEDIUM] CWE-79 CVE-2024-26081: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36150P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36150 [MEDIUM] CWE-79 CVE-2024-36150: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36168P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36168 [MEDIUM] CWE-79 CVE-2024-36168: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36154P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36154 [MEDIUM] CWE-79 CVE-2024-36154: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36170P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36170 [MEDIUM] CWE-79 CVE-2024-36170: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-20769P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-20769 [MEDIUM] CWE-79 CVE-2024-20769: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36156P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36156 [MEDIUM] CWE-79 CVE-2024-36156: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26095P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-26095 [MEDIUM] CWE-79 CVE-2024-26095: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36149P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36149 [MEDIUM] CWE-79 CVE-2024-36149: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36157P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36157 [MEDIUM] CWE-79 CVE-2024-36157: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36152P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36152 [MEDIUM] CWE-79 CVE-2024-36152: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36160P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36160 [MEDIUM] CWE-79 CVE-2024-36160: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-20784P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-20784 [MEDIUM] CWE-79 CVE-2024-20784: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36148P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36148 [MEDIUM] CWE-79 CVE-2024-36148: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd