cbcvebase.

Adobe Experience Manager vulnerabilities

1,019 known vulnerabilities affecting adobe/adobe_experience_manager.

Total CVEs
1,019
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL8HIGH14MEDIUM987LOW10

Vulnerabilities

Page 7 of 51
CVE-2026-47962P4MEDIUMCVSS 5.4≤ 2026.042026-06-09
CVE-2026-47962 [MEDIUM] CWE-79 CVE-2026-47962: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47957P4MEDIUMCVSS 5.4≤ 2026.042026-06-09
CVE-2026-47957 [MEDIUM] CWE-79 CVE-2026-47957: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47954P4MEDIUMCVSS 5.4≤ 2026.042026-06-09
CVE-2026-47954 [MEDIUM] CWE-79 CVE-2026-47954: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47980P4MEDIUMCVSS 5.4≤ 2026.042026-06-09
CVE-2026-47980 [MEDIUM] CWE-79 CVE-2026-47980: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47949P4MEDIUMCVSS 5.4≤ 2026.042026-06-09
CVE-2026-47949 [MEDIUM] CWE-79 CVE-2026-47949: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47973P4MEDIUMCVSS 5.4≤ 2026.042026-06-09
CVE-2026-47973 [MEDIUM] CWE-79 CVE-2026-47973: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47977P4MEDIUMCVSS 5.4≤ 2026.042026-06-09
CVE-2026-47977 [MEDIUM] CWE-79 CVE-2026-47977: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47981P4MEDIUMCVSS 5.4≤ 2026.042026-06-09
CVE-2026-47981 [MEDIUM] CWE-79 CVE-2026-47981: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47953P4MEDIUMCVSS 5.4≤ 2026.042026-06-09
CVE-2026-47953 [MEDIUM] CWE-79 CVE-2026-47953: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-48297P4MEDIUMCVSS 5.4≤ 2026.042026-06-09
CVE-2026-48297 [MEDIUM] CWE-79 CVE-2026-48297: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-48299P4MEDIUMCVSS 5.4≤ 2026.042026-06-09
CVE-2026-48299 [MEDIUM] CWE-79 CVE-2026-48299: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47958P4MEDIUMCVSS 5.4≤ 2026.042026-06-09
CVE-2026-47958 [MEDIUM] CWE-79 CVE-2026-47958: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47972P4MEDIUMCVSS 5.4≤ 2026.042026-06-09
CVE-2026-47972 [MEDIUM] CWE-79 CVE-2026-47972: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47956P4MEDIUMCVSS 5.4≤ 2026.042026-06-09
CVE-2026-47956 [MEDIUM] CWE-79 CVE-2026-47956: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47950P4MEDIUMCVSS 5.4≤ 2026.042026-06-09
CVE-2026-47950 [MEDIUM] CWE-79 CVE-2026-47950: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47944P4MEDIUMCVSS 5.4≤ 2026.042026-06-09
CVE-2026-47944 [MEDIUM] CWE-79 CVE-2026-47944: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-48300P4MEDIUMCVSS 5.4≤ 2026.042026-06-09
CVE-2026-48300 [MEDIUM] CWE-79 CVE-2026-48300: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-27228P4MEDIUMCVSS 5.4≤ 6.5.232026-03-11
CVE-2026-27228 [MEDIUM] CWE-79 CVE-2026-27228: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27231P4MEDIUMCVSS 5.4≤ 6.5.232026-03-11
CVE-2026-27231 [MEDIUM] CWE-79 CVE-2026-27231: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27229P4MEDIUMCVSS 5.4≤ 6.5.232026-03-11
CVE-2026-27229 [MEDIUM] CWE-79 CVE-2026-27229: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
Adobe Experience Manager vulnerabilities | cvebase