Adobe Experience Manager vulnerabilities
1,019 known vulnerabilities affecting adobe/adobe_experience_manager.
Total CVEs
1,019
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL8HIGH14MEDIUM987LOW10
Vulnerabilities
Page 51 of 51
CVE-2024-43717P4MEDIUMCVSS 4.3≤ 6.5.212024-12-10
CVE-2024-43717 [MEDIUM] CWE-284 CVE-2024-43717: Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Access Control vuln
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on confidentiality. Exploitation of this issue does not require user interaction.
nvd
CVE-2024-26049P4MEDIUMCVSS 4.8≤ 6.5.202024-06-13
CVE-2024-26049 [MEDIUM] CWE-79 CVE-2024-26049: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-43732P4MEDIUMCVSS 4.6≤ 6.5.212024-12-10
CVE-2024-43732 [MEDIUM] CWE-79 CVE-2024-43732: Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scriptin
Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could allow an attacker to execute arbitrary code in the context of the victim's browser. This issue occurs when data from a malicious source is processed by a web application's client-side scripts to update the DOM. Exploita
nvd
CVE-2025-46884P4MEDIUMCVSS 4.8≤ 6.5.222025-06-10
CVE-2025-46884 [MEDIUM] CWE-79 CVE-2025-46884: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46911P4MEDIUMCVSS 4.8≤ 6.5.222025-06-10
CVE-2025-46911 [MEDIUM] CWE-79 CVE-2025-46911: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-41842P4MEDIUMCVSS 4.8≤ 6.5.202024-08-23
CVE-2024-41842 [MEDIUM] CWE-79 CVE-2024-41842: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46913P4MEDIUMCVSS 4.8≤ 6.5.222025-06-10
CVE-2025-46913 [MEDIUM] CWE-79 CVE-2025-46913: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26050P4MEDIUMCVSS 4.8≤ 6.5.192024-03-18
CVE-2024-26050 [MEDIUM] CWE-79 CVE-2024-26050: Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-41849P4MEDIUMCVSS 4.1≤ 6.5.202024-08-23
CVE-2024-41849 [MEDIUM] CWE-20 CVE-2024-41849: Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vu
Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could lead to a security feature bypass. An low-privileged attacker could leverage this vulnerability to slightly affect the integrity of the page. Exploitation of this issue requires user interaction and scope is changed.
nvd
CVE-2026-48288P4LOWCVSS 3.5≤ 2026.042026-06-09
CVE-2026-48288 [LOW] CWE-20 CVE-2026-48288: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper I
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction
nvd
CVE-2026-48289P4LOWCVSS 3.5≤ 2026.042026-06-09
CVE-2026-48289 [LOW] CWE-20 CVE-2026-48289: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper I
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction
nvd
CVE-2024-52831P4LOWCVSS 3.5≤ 6.5.212024-12-10
CVE-2024-52831 [LOW] CWE-20 CVE-2024-52831: Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation vu
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and affect the integrity of the page. Exploitation of this issue requires user interaction.
nvd
CVE-2024-43755P4LOWCVSS 3.5≤ 6.5.212024-12-10
CVE-2024-43755 [LOW] CWE-20 CVE-2024-43755: Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation vu
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and affect the integrity of the page. Exploitation of this issue requires user interaction.
nvd
CVE-2025-47096P4LOWCVSS 3.5≤ 6.5.222025-06-10
CVE-2025-47096 [LOW] CWE-20 CVE-2025-47096: Adobe Experience Manager versions 6.5.22 and earlier are affected by an Improper Input Validation vu
Adobe Experience Manager versions 6.5.22 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass, allowing a low impact to the integrity of the component. Exploitation of this issue requires user interaction in that a victim must interact with the malicious content. Low privileges are require
nvd
CVE-2023-48608P4LOWCVSS 3.5≤ 6.5.182023-12-15
CVE-2023-48608 [LOW] CWE-20 CVE-2023-48608: Adobe Experience Manager versions 6.5.18 and earlier are affected by an Improper Input Validation vu
Adobe Experience Manager versions 6.5.18 and earlier are affected by an Improper Input Validation vulnerability. A low-privileged attacker could leverage this vulnerability to achieve a low-integrity impact within the application. Exploitation of this issue requires user interaction.
nvd
CVE-2024-26126P4LOWCVSS 3.5≤ 6.5.202024-06-13
CVE-2024-26126 [LOW] CWE-20 CVE-2024-26126: Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vu
Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and affect the integrity of the page. Exploitation of this issue requires user interaction.
nvd
CVE-2024-26127P4LOWCVSS 3.5≤ 6.5.202024-06-13
CVE-2024-26127 [LOW] CWE-20 CVE-2024-26127: Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vu
Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and affect the integrity of the page. Exploitation of this issue requires user interaction.
nvd
CVE-2024-36226P4LOWCVSS 3.5≤ 6.5.202024-06-13
CVE-2024-36226 [LOW] CWE-20 CVE-2024-36226: Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vu
Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and affect the integrity of the page. Exploitation of this issue requires user interaction.
nvd
CVE-2024-41839P4LOWCVSS 3.5≤ 6.5.202024-07-23
CVE-2024-41839 [LOW] CWE-20 CVE-2024-41839: Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vu
Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could lead to a security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and affect the integrity of the page. Exploitation of this issue requires user interaction.
nvd
← Previous51 / 51