cbcvebase.

Adobe Experience Manager vulnerabilities

929 known vulnerabilities affecting adobe/adobe_experience_manager.

Total CVEs
929
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL8HIGH14MEDIUM899LOW8

Vulnerabilities

Page 7 of 47
CVE-2025-64582P4MEDIUMCVSS 5.4≤ 6.5.232025-12-10
CVE-2025-64582 [MEDIUM] CWE-79 CVE-2025-64582: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-64875P4MEDIUMCVSS 5.4≤ 6.5.232025-12-10
CVE-2025-64875 [MEDIUM] CWE-79 CVE-2025-64875: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-64553P4MEDIUMCVSS 5.4≤ 6.5.232025-12-10
CVE-2025-64553 [MEDIUM] CWE-79 CVE-2025-64553: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-64829P4MEDIUMCVSS 5.4≤ 6.5.232025-12-10
CVE-2025-64829 [MEDIUM] CWE-79 CVE-2025-64829: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-64861P4MEDIUMCVSS 5.4≤ 6.5.232025-12-10
CVE-2025-64861 [MEDIUM] CWE-79 CVE-2025-64861: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-64800P4MEDIUMCVSS 5.4≤ 6.5.232025-12-10
CVE-2025-64800 [MEDIUM] CWE-79 CVE-2025-64800: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-64869P4MEDIUMCVSS 5.4≤ 6.5.232025-12-10
CVE-2025-64869 [MEDIUM] CWE-79 CVE-2025-64869: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-64547P4MEDIUMCVSS 5.4≤ 6.5.232025-12-10
CVE-2025-64547 [MEDIUM] CWE-79 CVE-2025-64547: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-64827P4MEDIUMCVSS 5.4≤ 6.5.232025-12-10
CVE-2025-64827 [MEDIUM] CWE-79 CVE-2025-64827: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36141P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36141 [MEDIUM] CWE-79 CVE-2024-36141: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26092P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-26092 [MEDIUM] CWE-79 CVE-2024-26092: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26054P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-26054 [MEDIUM] CWE-79 CVE-2024-26054: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26081P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-26081 [MEDIUM] CWE-79 CVE-2024-26081: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36150P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36150 [MEDIUM] CWE-79 CVE-2024-36150: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36168P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36168 [MEDIUM] CWE-79 CVE-2024-36168: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36154P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36154 [MEDIUM] CWE-79 CVE-2024-36154: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36170P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36170 [MEDIUM] CWE-79 CVE-2024-36170: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-20769P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-20769 [MEDIUM] CWE-79 CVE-2024-20769: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36156P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-36156 [MEDIUM] CWE-79 CVE-2024-36156: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26095P4MEDIUMCVSS 5.4≤ 6.5.202024-06-13
CVE-2024-26095 [MEDIUM] CWE-79 CVE-2024-26095: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
Adobe Experience Manager vulnerabilities | cvebase