cbcvebase.

Adobe Experience Manager vulnerabilities

929 known vulnerabilities affecting adobe/adobe_experience_manager.

Total CVEs
929
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL8HIGH14MEDIUM899LOW8

Vulnerabilities

Page 30 of 47
CVE-2024-36192P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36192 [MEDIUM] CWE-79 CVE-2024-36192: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36191P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36191 [MEDIUM] CWE-79 CVE-2024-36191: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36196P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36196 [MEDIUM] CWE-79 CVE-2024-36196: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36198P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36198 [MEDIUM] CWE-79 CVE-2024-36198: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36193P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36193 [MEDIUM] CWE-79 CVE-2024-36193: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36199P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36199 [MEDIUM] CWE-79 CVE-2024-36199: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36209P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36209 [MEDIUM] CWE-79 CVE-2024-36209: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36195P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36195 [MEDIUM] CWE-79 CVE-2024-36195: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26076P4MEDIUMCVSS 5.4≤ 6.5.192024-04-10
CVE-2024-26076 [MEDIUM] CWE-79 CVE-2024-26076: Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26097P4MEDIUMCVSS 5.4≤ 6.5.192024-04-10
CVE-2024-26097 [MEDIUM] CWE-79 CVE-2024-26097: Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26047P4MEDIUMCVSS 5.4≤ 6.5.192024-04-10
CVE-2024-26047 [MEDIUM] CWE-79 CVE-2024-26047: Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26098P4MEDIUMCVSS 5.4≤ 6.5.192024-04-10
CVE-2024-26098 [MEDIUM] CWE-79 CVE-2024-26098: Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26084P4MEDIUMCVSS 5.4≤ 6.5.192024-04-10
CVE-2024-26084 [MEDIUM] CWE-79 CVE-2024-26084: Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26079P4MEDIUMCVSS 5.4≤ 6.5.192024-04-10
CVE-2024-26079 [MEDIUM] CWE-79 CVE-2024-26079: Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-53963P4MEDIUMCVSS 5.4≤ 6.5.212025-02-05
CVE-2024-53963 [MEDIUM] CWE-79 CVE-2024-53963: Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scriptin Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URL or user input, the attacker can inject malicious sc
nvd
CVE-2024-53965P4MEDIUMCVSS 5.4≤ 6.5.212025-02-05
CVE-2024-53965 [MEDIUM] CWE-79 CVE-2024-53965: Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scriptin Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URL or user input, the attacker can inject malicious sc
nvd
CVE-2024-36176P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36176 [MEDIUM] CWE-79 CVE-2024-36176: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36178P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36178 [MEDIUM] CWE-79 CVE-2024-36178: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36177P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36177 [MEDIUM] CWE-79 CVE-2024-36177: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36175P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36175 [MEDIUM] CWE-79 CVE-2024-36175: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
Adobe Experience Manager vulnerabilities | cvebase