Adobe Connect vulnerabilities

67 known vulnerabilities affecting adobe/connect.

Total CVEs
67
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH9MEDIUM44

Vulnerabilities

Page 1 of 4
CVE-2025-49553CRITICALCVSS 9.3fixed in 12.102025-10-14
CVE-2025-49553 [CRITICAL] CWE-79 CVE-2025-49553: Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulne Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute malicious scripts in a victim's browser. Exploitation of this issue requires user interaction in that a victim must navigate to a crafted web page. A successful attacker can abuse this to ach
nvd
CVE-2025-49552HIGHCVSS 8.1fixed in 12.102025-10-14
CVE-2025-49552 [HIGH] CWE-79 CVE-2025-49552: Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulne Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a high-privileged attacker to execute malicious scripts in a victim's browser. Exploitation of this issue requires user interaction in that a victim must navigate to a crafted web page. A successful attacker can abuse
nvd
CVE-2025-54196MEDIUMCVSS 6.1fixed in 12.102025-10-14
CVE-2025-54196 [LOW] CWE-601 CVE-2025-54196: Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open R Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction in that a victim must click on a crafted link.
nvd
CVE-2025-27203CRITICALCVSS 9.6fixed in 2025.5.52025-07-08
CVE-2025-27203 [CRITICAL] CWE-502 CVE-2025-27203: Adobe Connect versions 24.0 and earlier are affected by a Deserialization of Untrusted Data vulnerab Adobe Connect versions 24.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does require user interaction and scope is changed.
nvd
CVE-2025-43567CRITICALCVSS 9.3fixed in 12.92025-05-13
CVE-2025-43567 [CRITICAL] CWE-79 CVE-2025-43567: Adobe Connect versions 12.8 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulne Adobe Connect versions 12.8 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can a
nvd
CVE-2025-30316MEDIUMCVSS 5.4fixed in 12.92025-05-13
CVE-2025-30316 [MEDIUM] CWE-79 CVE-2025-30316: Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerab Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-30315MEDIUMCVSS 6.1fixed in 12.92025-05-13
CVE-2025-30315 [MEDIUM] CWE-79 CVE-2025-30315: Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerab Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-30314MEDIUMCVSS 6.1fixed in 12.92025-05-13
CVE-2025-30314 [MEDIUM] CWE-79 CVE-2025-30314: Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerab Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-54034CRITICALCVSS 9.3fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-54034 [CRITICAL] CWE-79 CVE-2024-54034: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XS Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. A successful attacker can abuse this to achieve sessi
nvd
CVE-2024-54032CRITICALCVSS 9.3fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-54032 [CRITICAL] CWE-79 CVE-2024-54032: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker c
nvd
CVE-2024-54036CRITICALCVSS 9.3fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-54036 [CRITICAL] CWE-79 CVE-2024-54036: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker c
nvd
CVE-2024-54037HIGHCVSS 8.1fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-54037 [HIGH] CWE-79 CVE-2024-54037: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a DOM-based Cross-Site Scripting (XS Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URL or user input, the high-privileged attacker can inject malicious scripts
nvd
CVE-2024-54039MEDIUMCVSS 5.4fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-54039 [MEDIUM] CWE-79 CVE-2024-54039: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-54047MEDIUMCVSS 6.1fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-54047 [MEDIUM] CWE-79 CVE-2024-54047: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XS Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2024-49550MEDIUMCVSS 6.1fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-49550 [MEDIUM] CWE-79 CVE-2024-49550: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XS Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2024-54048MEDIUMCVSS 6.1fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-54048 [MEDIUM] CWE-79 CVE-2024-54048: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XS Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2024-54051MEDIUMCVSS 6.1fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-54051 [MEDIUM] CWE-601 CVE-2024-54051: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a URL Redirection to Untrusted Site Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.
nvd
CVE-2024-54045MEDIUMCVSS 6.1fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-54045 [MEDIUM] CWE-79 CVE-2024-54045: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XS Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2024-54043MEDIUMCVSS 6.1fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-54043 [MEDIUM] CWE-79 CVE-2024-54043: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XS Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2024-54040MEDIUMCVSS 5.4fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-54040 [MEDIUM] CWE-79 CVE-2024-54040: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
Adobe Connect vulnerabilities | cvebase