Adobe Connect vulnerabilities
77 known vulnerabilities affecting adobe/connect.
Total CVEs
77
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL18HIGH10MEDIUM48LOW1
Vulnerabilities
Page 2 of 4
CVE-2025-43567P3CRITICALCVSS 9.3fixed in 12.92025-05-13
CVE-2025-43567 [CRITICAL] CWE-79 CVE-2025-43567: Adobe Connect versions 12.8 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulne
Adobe Connect versions 12.8 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can a
nvd
CVE-2026-27246P3CRITICALCVSS 9.3fixed in 12.112026-04-14
CVE-2026-27246 [CRITICAL] CWE-79 CVE-2026-27246: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (X
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in
nvd
CVE-2026-27245P3CRITICALCVSS 9.3fixed in 12.112026-04-14
CVE-2026-27245 [CRITICAL] CWE-79 CVE-2026-27245: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (X
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in
nvd
CVE-2026-27243P3CRITICALCVSS 9.3fixed in 12.112026-04-14
CVE-2026-27243 [CRITICAL] CWE-79 CVE-2026-27243: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (X
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in
nvd
CVE-2021-21085P3HIGHCVSS 7.8≤ 11.0.7≥ unspecified, ≤ 11.0.72021-03-12
CVE-2021-21085 [HIGH] CWE-20 CVE-2021-21085: Adobe Connect version 11.0.7 (and earlier) is affected by an Input Validation vulnerability in the e
Adobe Connect version 11.0.7 (and earlier) is affected by an Input Validation vulnerability in the export feature. An attacker could exploit this vulnerability by injecting a payload into an online event form and achieve code execution if the victim exports and opens the data on their local machine.
nvd
CVE-2017-3101P3HIGHCVSS 7.5≤ 9.6.12017-07-17
CVE-2017-3101 [HIGH] CVE-2017-3101: Adobe Connect versions 9.6.1 and earlier have a clickjacking vulnerability. Successful exploitation
Adobe Connect versions 9.6.1 and earlier have a clickjacking vulnerability. Successful exploitation could lead to a clickjacking attack.
nvd
CVE-2016-0948P3HIGHCVSS 8.8≤ 9.52016-02-10
CVE-2016-0948 [HIGH] CWE-352 CVE-2016-0948: Cross-site request forgery (CSRF) vulnerability in Adobe Connect before 9.5.2 allows remote attacker
Cross-site request forgery (CSRF) vulnerability in Adobe Connect before 9.5.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
nvd
CVE-2024-54037P3HIGHCVSS 8.1fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-54037 [HIGH] CWE-79 CVE-2024-54037: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a DOM-based Cross-Site Scripting (XS
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URL or user input, the high-privileged attacker can inject malicious scripts
nvd
CVE-2025-49552P3HIGHCVSS 8.1fixed in 12.102025-10-14
CVE-2025-49552 [HIGH] CWE-79 CVE-2025-49552: Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulne
Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a high-privileged attacker to execute malicious scripts in a victim's browser. Exploitation of this issue requires user interaction in that a victim must navigate to a crafted web page. A successful attacker can abuse
nvd
CVE-2016-4118P4HIGHCVSS 7.8≤ 9.5.22016-05-30
CVE-2016-4118 [HIGH] CWE-264 CVE-2016-4118: Untrusted search path vulnerability in the installer in Adobe Connect Add-In before 11.9.976.291 on
Untrusted search path vulnerability in the installer in Adobe Connect Add-In before 11.9.976.291 on Windows allows local users to gain privileges via unspecified vectors.
nvd
CVE-2018-4921P4MEDIUMCVSS 6.1≤ 9.72018-05-19
CVE-2018-4921 [MEDIUM] CWE-434 CVE-2018-4921: Adobe Connect versions 9.7 and earlier have an exploitable unrestricted SWF file upload vulnerabilit
Adobe Connect versions 9.7 and earlier have an exploitable unrestricted SWF file upload vulnerability. Successful exploitation could lead to information disclosure.
nvd
CVE-2025-54196P4MEDIUMCVSS 6.1fixed in 12.102025-10-14
CVE-2025-54196 [MEDIUM] CWE-601 CVE-2025-54196: Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open R
Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction in that a victim must click on a crafted link.
nvd
CVE-2016-0950P4MEDIUMCVSS 5.3≤ 9.5.22016-02-10
CVE-2016-0950 [MEDIUM] CWE-20 CVE-2016-0950: Adobe Connect before 9.5.2 allows remote attackers to spoof the user interface via unspecified vecto
Adobe Connect before 9.5.2 allows remote attackers to spoof the user interface via unspecified vectors.
nvd
CVE-2017-3103P4MEDIUMCVSS 6.1≤ 9.6.12017-07-17
CVE-2017-3103 [MEDIUM] CWE-79 CVE-2017-3103: Adobe Connect versions 9.6.1 and earlier have a stored cross-site scripting vulnerability. Successfu
Adobe Connect versions 9.6.1 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to a stored cross-site scripting attack.
nvd
CVE-2017-11290P4MEDIUMCVSS 6.1≤ 9.6.22017-12-09
CVE-2017-11290 [MEDIUM] CWE-1021 CVE-2017-11290: An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A UI Redress (or Clickjacking)
An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A UI Redress (or Clickjacking) vulnerability exists. This issue has been resolved by adding a feature that enables Connect administrators to protect users from UI redressing (or clickjacking) attacks.
nvd
CVE-2021-36061P4MEDIUMCVSS 5.4≤ 11.2.2≥ unspecified, ≤ 11.2.22021-09-01
CVE-2021-36061 [MEDIUM] CWE-657 CVE-2021-36061: Adobe Connect version 11.2.2 (and earlier) is affected by a secure design principles violation vulne
Adobe Connect version 11.2.2 (and earlier) is affected by a secure design principles violation vulnerability via the 'pbMode' parameter. An unauthenticated attacker could leverage this vulnerability to edit or delete recordings on the Connect environment. Exploitation of this issue requires user interaction in that a victim must publish a link of a
nvd
CVE-2021-36062P4MEDIUMCVSS 6.1≤ 11.2.2≥ unspecified, ≤ 11.2.22021-09-01
CVE-2021-36062 [MEDIUM] CWE-79 CVE-2021-36062: Adobe Connect version 11.2.2 (and earlier) is affected by a Reflected Cross-site Scripting vulnerabi
Adobe Connect version 11.2.2 (and earlier) is affected by a Reflected Cross-site Scripting vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context
nvd
CVE-2024-54051P4MEDIUMCVSS 6.1fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-54051 [MEDIUM] CWE-601 CVE-2024-54051: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a URL Redirection to Untrusted Site
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.
nvd
CVE-2024-54050P4MEDIUMCVSS 6.1fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-54050 [MEDIUM] CWE-601 CVE-2024-54050: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a URL Redirection to Untrusted Site
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.
nvd
CVE-2024-54042P4MEDIUMCVSS 6.1fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-54042 [MEDIUM] CWE-79 CVE-2024-54042: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XS
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd