cbcvebase.

Adobe Experience Manager vulnerabilities

1,019 known vulnerabilities affecting adobe/adobe_experience_manager.

Total CVEs
1,019
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL8HIGH14MEDIUM987LOW10

Vulnerabilities

Page 13 of 51
CVE-2024-43744P4MEDIUMCVSS 5.4≤ 6.5.212024-12-10
CVE-2024-43744 [MEDIUM] CWE-79 CVE-2024-43744: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-43747P4MEDIUMCVSS 5.4≤ 6.5.212024-12-10
CVE-2024-43747 [MEDIUM] CWE-79 CVE-2024-43747: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-43739P4MEDIUMCVSS 5.4≤ 6.5.212024-12-10
CVE-2024-43739 [MEDIUM] CWE-79 CVE-2024-43739: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26123P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-26123 [MEDIUM] CWE-79 CVE-2024-26123: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26078P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-26078 [MEDIUM] CWE-79 CVE-2024-26078: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26082P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-26082 [MEDIUM] CWE-79 CVE-2024-26082: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36142P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36142 [MEDIUM] CWE-79 CVE-2024-36142: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36144P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36144 [MEDIUM] CWE-79 CVE-2024-36144: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26121P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-26121 [MEDIUM] CWE-79 CVE-2024-26121: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-34120P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-34120 [MEDIUM] CWE-79 CVE-2024-34120: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-34119P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-34119 [MEDIUM] CWE-79 CVE-2024-34119: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36143P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36143 [MEDIUM] CWE-79 CVE-2024-36143: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26085P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-26085 [MEDIUM] CWE-79 CVE-2024-26085: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48616P4MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48616 [MEDIUM] CWE-79 CVE-2023-48616: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48538P4MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48538 [MEDIUM] CWE-79 CVE-2023-48538: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48588P4MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48588 [MEDIUM] CWE-79 CVE-2023-48588: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48600P4MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48600 [MEDIUM] CWE-79 CVE-2023-48600: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48553P4MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48553 [MEDIUM] CWE-79 CVE-2023-48553: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48543P4MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48543 [MEDIUM] CWE-79 CVE-2023-48543: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48577P4MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48577 [MEDIUM] CWE-79 CVE-2023-48577: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
Adobe Experience Manager vulnerabilities | cvebase