cbcvebase.

Adobe Experience Manager vulnerabilities

1,019 known vulnerabilities affecting adobe/adobe_experience_manager.

Total CVEs
1,019
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL8HIGH14MEDIUM987LOW10

Vulnerabilities

Page 49 of 51
CVE-2025-46874P4MEDIUMCVSS 5.4≤ 6.5.222025-06-10
CVE-2025-46874 [MEDIUM] CWE-79 CVE-2025-46874: Adobe Experience Manager versions 6.5.22 and earlier are affected by a reflected Cross-Site Scriptin Adobe Experience Manager versions 6.5.22 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2025-46875P4MEDIUMCVSS 5.4≤ 6.5.222025-06-10
CVE-2025-46875 [MEDIUM] CWE-79 CVE-2025-46875: Adobe Experience Manager versions 6.5.22 and earlier are affected by a reflected Cross-Site Scriptin Adobe Experience Manager versions 6.5.22 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2025-46857P4MEDIUMCVSS 5.4≤ 6.5.222025-06-10
CVE-2025-46857 [MEDIUM] CWE-79 CVE-2025-46857: Adobe Experience Manager versions 6.5.22 and earlier are affected by a reflected Cross-Site Scriptin Adobe Experience Manager versions 6.5.22 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2025-46920P4MEDIUMCVSS 4.6≤ 6.5.222025-06-10
CVE-2025-46920 [MEDIUM] CWE-79 CVE-2025-46920: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2018-19727P4MEDIUMCVSS 6.1v6.4, 6.3, 6.2, 6.1, and 6.0 versions2019-01-28
CVE-2018-19727 [MEDIUM] CWE-79 CVE-2018-19727: Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
nvd
CVE-2018-15971P4MEDIUMCVSS 6.1v6.4, 6.3, 6.2, 6.1, and 6.0 versions2018-10-17
CVE-2018-15971 [MEDIUM] CWE-79 CVE-2018-15971: Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
nvd
CVE-2018-15970P4MEDIUMCVSS 6.1v6.4, 6.3, 6.2, 6.1, and 6.0 versions2018-10-17
CVE-2018-15970 [MEDIUM] CWE-79 CVE-2018-15970: Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
nvd
CVE-2019-8078P4MEDIUMCVSS 6.1v6.4, 6.3, 6.22019-10-24
CVE-2019-8078 [MEDIUM] CWE-79 CVE-2019-8078: Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a reflected cross site scripting vulnerabili Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a reflected cross site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
nvd
CVE-2019-8083P4MEDIUMCVSS 6.1v6.5, 6.4, 6.32019-10-25
CVE-2019-8083 [MEDIUM] CWE-79 CVE-2019-8083: Adobe Experience Manager versions 6.5, 6.4 and 6.3 have a cross site scripting vulnerability. Succes Adobe Experience Manager versions 6.5, 6.4 and 6.3 have a cross site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
nvd
CVE-2023-48447P4MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48447 [MEDIUM] CWE-79 CVE-2023-48447: Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scriptin Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48497P4MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48497 [MEDIUM] CWE-79 CVE-2023-48497: Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scriptin Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48498P4MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48498 [MEDIUM] CWE-79 CVE-2023-48498: Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scriptin Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48499P4MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48499 [MEDIUM] CWE-79 CVE-2023-48499: Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scriptin Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48443P4MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48443 [MEDIUM] CWE-79 CVE-2023-48443: Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scriptin Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48448P4MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48448 [MEDIUM] CWE-79 CVE-2023-48448: Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scriptin Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48500P4MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48500 [MEDIUM] CWE-79 CVE-2023-48500: Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scriptin Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48526P4MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48526 [MEDIUM] CWE-79 CVE-2023-48526: Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scriptin Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-29322P4MEDIUMCVSS 5.4≤ 6.5.16.02023-06-15
CVE-2023-29322 [MEDIUM] CWE-79 CVE-2023-29322: Adobe Experience Manager versions 6.5.16.0 (and earlier) is affected by a reflected Cross-Site Scrip Adobe Experience Manager versions 6.5.16.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-29304P4MEDIUMCVSS 5.4≤ 6.5.16.02023-06-15
CVE-2023-29304 [MEDIUM] CWE-79 CVE-2023-29304: Adobe Experience Manager versions 6.5.16.0 (and earlier) is affected by a reflected Cross-Site Scrip Adobe Experience Manager versions 6.5.16.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-29302P4MEDIUMCVSS 5.4≤ 6.5.16.02023-06-15
CVE-2023-29302 [MEDIUM] CWE-79 CVE-2023-29302: Adobe Experience Manager versions 6.5.16.0 (and earlier) is affected by a reflected Cross-Site Scrip Adobe Experience Manager versions 6.5.16.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
Adobe Experience Manager vulnerabilities | cvebase