Adobe Experience Manager vulnerabilities
1,019 known vulnerabilities affecting adobe/adobe_experience_manager.
Total CVEs
1,019
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL8HIGH14MEDIUM987LOW10
Vulnerabilities
Page 20 of 51
CVE-2024-53962P4MEDIUMCVSS 5.4≤ 6.5.212025-02-05
CVE-2024-53962 [MEDIUM] CWE-79 CVE-2024-53962: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-51464P4MEDIUMCVSS 5.4≤ 6.5.182024-01-18
CVE-2023-51464 [MEDIUM] CWE-79 CVE-2023-51464: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-51460P4MEDIUMCVSS 5.4≤ 6.5.182023-12-20
CVE-2023-51460 [MEDIUM] CWE-79 CVE-2023-51460: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-51457P4MEDIUMCVSS 5.4≤ 6.5.182023-12-20
CVE-2023-51457 [MEDIUM] CWE-79 CVE-2023-51457: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-51461P4MEDIUMCVSS 5.4≤ 6.5.182023-12-20
CVE-2023-51461 [MEDIUM] CWE-79 CVE-2023-51461: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-51458P4MEDIUMCVSS 5.4≤ 6.5.182023-12-20
CVE-2023-51458 [MEDIUM] CWE-79 CVE-2023-51458: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-45153P4MEDIUMCVSS 5.4≤ 6.5.202024-10-07
CVE-2024-45153 [MEDIUM] CWE-79 CVE-2024-45153: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47071P4MEDIUMCVSS 5.4≤ 6.5.222025-06-10
CVE-2025-47071 [MEDIUM] CWE-79 CVE-2025-47071: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47074P4MEDIUMCVSS 5.4≤ 6.5.222025-06-10
CVE-2025-47074 [MEDIUM] CWE-79 CVE-2025-47074: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46898P4MEDIUMCVSS 5.4≤ 6.5.222025-06-10
CVE-2025-46898 [MEDIUM] CWE-79 CVE-2025-46898: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46890P4MEDIUMCVSS 5.4≤ 6.5.222025-06-10
CVE-2025-46890 [MEDIUM] CWE-79 CVE-2025-46890: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46877P4MEDIUMCVSS 5.4≤ 6.5.222025-06-10
CVE-2025-46877 [MEDIUM] CWE-79 CVE-2025-46877: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46872P4MEDIUMCVSS 5.4≤ 6.5.222025-06-10
CVE-2025-46872 [MEDIUM] CWE-79 CVE-2025-46872: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-34142P4MEDIUMCVSS 5.4≤ 6.5.202024-06-25
CVE-2024-34142 [MEDIUM] CWE-79 CVE-2024-34142: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-34141P4MEDIUMCVSS 5.4≤ 6.5.202024-06-25
CVE-2024-34141 [MEDIUM] CWE-79 CVE-2024-34141: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47092P4MEDIUMCVSS 5.4≤ 6.5.222025-06-10
CVE-2025-47092 [MEDIUM] CWE-79 CVE-2025-47092: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47004P4MEDIUMCVSS 5.4≤ 6.5.222025-06-10
CVE-2025-47004 [MEDIUM] CWE-79 CVE-2025-47004: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46984P4MEDIUMCVSS 5.4≤ 6.5.222025-06-10
CVE-2025-46984 [MEDIUM] CWE-79 CVE-2025-46984: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47052P4MEDIUMCVSS 5.4≤ 6.5.222025-06-10
CVE-2025-47052 [MEDIUM] CWE-79 CVE-2025-47052: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46986P4MEDIUMCVSS 5.4≤ 6.5.222025-06-10
CVE-2025-46986 [MEDIUM] CWE-79 CVE-2025-46986: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd