cbcvebase.

Adobe Experience Manager vulnerabilities

929 known vulnerabilities affecting adobe/adobe_experience_manager.

Total CVEs
929
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL8HIGH14MEDIUM899LOW8

Vulnerabilities

Page 28 of 47
CVE-2025-47061P4MEDIUMCVSS 5.4≤ 6.5.222025-07-24
CVE-2025-47061 [MEDIUM] CWE-79 CVE-2025-47061: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46993P4MEDIUMCVSS 5.4≤ 6.5.222025-07-24
CVE-2025-46993 [MEDIUM] CWE-79 CVE-2025-46993: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46996P4MEDIUMCVSS 5.4≤ 6.5.222025-07-24
CVE-2025-46996 [MEDIUM] CWE-79 CVE-2025-46996: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-53974P4MEDIUMCVSS 5.4≤ 6.5.212025-02-19
CVE-2024-53974 [MEDIUM] CWE-79 CVE-2024-53974: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47090P4MEDIUMCVSS 5.4≤ 6.5.222025-06-10
CVE-2025-47090 [MEDIUM] CWE-79 CVE-2025-47090: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47093P4MEDIUMCVSS 5.4≤ 6.5.222025-06-10
CVE-2025-47093 [MEDIUM] CWE-79 CVE-2025-47093: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47087P4MEDIUMCVSS 5.4≤ 6.5.222025-06-10
CVE-2025-47087 [MEDIUM] CWE-79 CVE-2025-47087: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47086P4MEDIUMCVSS 5.4≤ 6.5.222025-06-10
CVE-2025-47086 [MEDIUM] CWE-79 CVE-2025-47086: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47082P4MEDIUMCVSS 5.4≤ 6.5.222025-06-10
CVE-2025-47082 [MEDIUM] CWE-79 CVE-2025-47082: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47089P4MEDIUMCVSS 5.4≤ 6.5.222025-06-10
CVE-2025-47089 [MEDIUM] CWE-79 CVE-2025-47089: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-49547P4MEDIUMCVSS 5.4≤ FP11.42025-07-08
CVE-2025-49547 [MEDIUM] CWE-79 CVE-2025-49547: Adobe Experience Manager versions FP11.4 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions FP11.4 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Scope
nvd
CVE-2025-49534P4MEDIUMCVSS 5.4≤ FP11.42025-07-08
CVE-2025-49534 [MEDIUM] CWE-79 CVE-2025-49534: Adobe Experience Manager versions FP11.4 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions FP11.4 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Scope
nvd
CVE-2025-46852P4MEDIUMCVSS 5.4≤ 6.5.222025-08-20
CVE-2025-46852 [MEDIUM] CWE-79 CVE-2025-46852: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46932P4MEDIUMCVSS 5.4≤ 6.5.222025-08-20
CVE-2025-46932 [MEDIUM] CWE-79 CVE-2025-46932: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46998P4MEDIUMCVSS 5.4≤ 6.5.222025-08-20
CVE-2025-46998 [MEDIUM] CWE-79 CVE-2025-46998: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46936P4MEDIUMCVSS 5.4≤ 6.5.222025-08-20
CVE-2025-46936 [MEDIUM] CWE-79 CVE-2025-46936: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46849P4MEDIUMCVSS 5.4≤ 6.5.222025-08-20
CVE-2025-46849 [MEDIUM] CWE-79 CVE-2025-46849: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46962P4MEDIUMCVSS 5.4≤ 6.5.222025-08-20
CVE-2025-46962 [MEDIUM] CWE-79 CVE-2025-46962: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-52837P4MEDIUMCVSS 5.4≤ 6.5.212024-12-10
CVE-2024-52837 [MEDIUM] CWE-79 CVE-2024-52837: Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scriptin Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URL or user input, the attacker can inject malicious scripts that run
nvd
CVE-2024-52844P4MEDIUMCVSS 5.4≤ 6.5.212024-12-10
CVE-2024-52844 [MEDIUM] CWE-79 CVE-2024-52844: Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scriptin Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URL or user input, the attacker can inject malicious scripts that run
nvd
Adobe Experience Manager vulnerabilities | cvebase