Adobe Connect vulnerabilities
77 known vulnerabilities affecting adobe/connect.
Total CVEs
77
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL18HIGH10MEDIUM48LOW1
Vulnerabilities
Page 1 of 4
CVE-2026-27245CRITICALCVSS 9.3fixed in 12.112026-04-14
CVE-2026-27245 [CRITICAL] CWE-79 CVE-2026-27245: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (X
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in
nvd
CVE-2026-27303CRITICALCVSS 9.6fixed in 12.112026-04-14
CVE-2026-27303 [CRITICAL] CWE-502 CVE-2026-27303: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scop
nvd
CVE-2026-27243CRITICALCVSS 9.3fixed in 12.112026-04-14
CVE-2026-27243 [CRITICAL] CWE-79 CVE-2026-27243: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (X
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in
nvd
CVE-2026-34615CRITICALCVSS 9.3fixed in 12.112026-04-14
CVE-2026-34615 [CRITICAL] CWE-502 CVE-2026-34615: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim
nvd
CVE-2026-27246CRITICALCVSS 9.3fixed in 12.112026-04-14
CVE-2026-27246 [CRITICAL] CWE-79 CVE-2026-27246: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (X
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in
nvd
CVE-2026-34617HIGHCVSS 8.7fixed in 12.112026-04-14
CVE-2026-34617 [HIGH] CWE-79 CVE-2026-34617: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Cross-Site Scripting (XSS) vulner
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation o
nvd
CVE-2026-21331MEDIUMCVSS 6.1fixed in 12.112026-04-14
CVE-2026-21331 [MEDIUM] CWE-79 CVE-2026-21331: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (X
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Scope is changed.
nvd
CVE-2026-34614MEDIUMCVSS 6.1fixed in 12.112026-04-14
CVE-2026-34614 [MEDIUM] CWE-79 CVE-2026-34614: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (X
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Scope is changed.
nvd
CVE-2025-49553CRITICALCVSS 9.3fixed in 12.102025-10-14
CVE-2025-49553 [CRITICAL] CWE-79 CVE-2025-49553: Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulne
Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute malicious scripts in a victim's browser. Exploitation of this issue requires user interaction in that a victim must navigate to a crafted web page. A successful attacker can abuse this to ach
nvd
CVE-2025-49552HIGHCVSS 8.1fixed in 12.102025-10-14
CVE-2025-49552 [HIGH] CWE-79 CVE-2025-49552: Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulne
Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a high-privileged attacker to execute malicious scripts in a victim's browser. Exploitation of this issue requires user interaction in that a victim must navigate to a crafted web page. A successful attacker can abuse
nvd
CVE-2025-54196MEDIUMCVSS 6.1fixed in 12.102025-10-14
CVE-2025-54196 [MEDIUM] CWE-601 CVE-2025-54196: Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open R
Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction in that a victim must click on a crafted link.
nvd
CVE-2025-43567CRITICALCVSS 9.3fixed in 12.92025-05-13
CVE-2025-43567 [CRITICAL] CWE-79 CVE-2025-43567: Adobe Connect versions 12.8 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulne
Adobe Connect versions 12.8 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can a
nvd
CVE-2025-30316MEDIUMCVSS 5.4fixed in 12.92025-05-13
CVE-2025-30316 [MEDIUM] CWE-79 CVE-2025-30316: Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerab
Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-30315MEDIUMCVSS 6.1fixed in 12.92025-05-13
CVE-2025-30315 [MEDIUM] CWE-79 CVE-2025-30315: Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerab
Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-30314MEDIUMCVSS 6.1fixed in 12.92025-05-13
CVE-2025-30314 [MEDIUM] CWE-79 CVE-2025-30314: Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerab
Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-54034CRITICALCVSS 9.3fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-54034 [CRITICAL] CWE-79 CVE-2024-54034: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XS
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. A successful attacker can abuse this to achieve sessi
nvd
CVE-2024-54032CRITICALCVSS 9.3fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-54032 [CRITICAL] CWE-79 CVE-2024-54032: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS)
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker c
nvd
CVE-2024-54036CRITICALCVSS 9.3fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-54036 [CRITICAL] CWE-79 CVE-2024-54036: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS)
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker c
nvd
CVE-2024-54037HIGHCVSS 8.1fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-54037 [HIGH] CWE-79 CVE-2024-54037: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a DOM-based Cross-Site Scripting (XS
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URL or user input, the high-privileged attacker can inject malicious scripts
nvd
CVE-2024-54039MEDIUMCVSS 5.4fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-54039 [MEDIUM] CWE-79 CVE-2024-54039: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS)
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
1 / 4Next →