Adobe Experience Manager vulnerabilities
962 known vulnerabilities affecting adobe/adobe_experience_manager.
Total CVEs
962
CISA KEV
1
actively exploited
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH14MEDIUM932LOW8
Vulnerabilities
Page 43 of 49
CVE-2023-48443MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48443 [MEDIUM] CWE-79 CVE-2023-48443: Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scriptin
Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48515MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48515 [MEDIUM] CWE-79 CVE-2023-48515: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48468MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48468 [MEDIUM] CWE-79 CVE-2023-48468: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48519MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48519 [MEDIUM] CWE-79 CVE-2023-48519: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48495MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48495 [MEDIUM] CWE-79 CVE-2023-48495: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48619MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48619 [MEDIUM] CWE-79 CVE-2023-48619: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48604MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48604 [MEDIUM] CWE-79 CVE-2023-48604: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48513MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48513 [MEDIUM] CWE-79 CVE-2023-48513: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48546MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48546 [MEDIUM] CWE-79 CVE-2023-48546: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48621MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48621 [MEDIUM] CWE-79 CVE-2023-48621: Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scriptin
Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48596MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48596 [MEDIUM] CWE-79 CVE-2023-48596: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48559MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48559 [MEDIUM] CWE-79 CVE-2023-48559: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48599MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48599 [MEDIUM] CWE-79 CVE-2023-48599: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48540MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48540 [MEDIUM] CWE-79 CVE-2023-48540: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48556MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48556 [MEDIUM] CWE-79 CVE-2023-48556: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48463MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48463 [MEDIUM] CWE-79 CVE-2023-48463: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48472MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48472 [MEDIUM] CWE-79 CVE-2023-48472: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48461MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48461 [MEDIUM] CWE-79 CVE-2023-48461: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48453MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48453 [MEDIUM] CWE-79 CVE-2023-48453: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48583MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48583 [MEDIUM] CWE-79 CVE-2023-48583: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd