cbcvebase.

Adobe Connect vulnerabilities

77 known vulnerabilities affecting adobe/connect.

Total CVEs
77
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL18HIGH10MEDIUM48LOW1

Vulnerabilities

Page 3 of 4
CVE-2024-54047P4MEDIUMCVSS 6.1fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-54047 [MEDIUM] CWE-79 CVE-2024-54047: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XS Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2024-54048P4MEDIUMCVSS 6.1fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-54048 [MEDIUM] CWE-79 CVE-2024-54048: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XS Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2024-54045P4MEDIUMCVSS 6.1fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-54045 [MEDIUM] CWE-79 CVE-2024-54045: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XS Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2024-54043P4MEDIUMCVSS 6.1fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-54043 [MEDIUM] CWE-79 CVE-2024-54043: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XS Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2024-54046P4MEDIUMCVSS 6.1fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-54046 [MEDIUM] CWE-79 CVE-2024-54046: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XS Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2024-54044P4MEDIUMCVSS 6.1fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-54044 [MEDIUM] CWE-79 CVE-2024-54044: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XS Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2025-30314P4MEDIUMCVSS 6.1fixed in 12.92025-05-13
CVE-2025-30314 [MEDIUM] CWE-79 CVE-2025-30314: Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerab Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-21331P4MEDIUMCVSS 6.1fixed in 12.112026-04-14
CVE-2026-21331 [MEDIUM] CWE-79 CVE-2026-21331: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (X Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Scope is changed.
nvd
CVE-2025-30315P4MEDIUMCVSS 6.1fixed in 12.92025-05-13
CVE-2025-30315 [MEDIUM] CWE-79 CVE-2025-30315: Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerab Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-30316P4MEDIUMCVSS 5.4fixed in 12.92025-05-13
CVE-2025-30316 [MEDIUM] CWE-79 CVE-2025-30316: Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerab Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2020-24442P4MEDIUMCVSS 6.1≤ 11.0≥ unspecified, ≤ 11.02020-11-12
CVE-2020-24442 [MEDIUM] CWE-79 CVE-2020-24442: Adobe Connect version 11.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulne Adobe Connect version 11.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2020-24443P4MEDIUMCVSS 6.1≤ 11.0≥ unspecified, ≤ 11.02020-11-12
CVE-2020-24443 [MEDIUM] CWE-79 CVE-2020-24443: Adobe Connect version 11.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulne Adobe Connect version 11.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2018-19718P4MEDIUMCVSS 5.3≤ 9.8.12019-01-18
CVE-2018-19718 [MEDIUM] CWE-200 CVE-2018-19718: Adobe Connect versions 9.8.1 and earlier have a session token exposure vulnerability. Successful exp Adobe Connect versions 9.8.1 and earlier have a session token exposure vulnerability. Successful exploitation could lead to exposure of the privileges granted to a session.
nvd
CVE-2021-36063P4MEDIUMCVSS 6.1≤ 11.2.2≥ unspecified, ≤ 11.2.22021-09-01
CVE-2021-36063 [MEDIUM] CWE-79 CVE-2021-36063: Adobe Connect version 11.2.2 (and earlier) is affected by a Reflected Cross-site Scripting vulnerabi Adobe Connect version 11.2.2 (and earlier) is affected by a Reflected Cross-site Scripting vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-49550P4MEDIUMCVSS 6.1fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-49550 [MEDIUM] CWE-79 CVE-2024-49550: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XS Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2026-34614P4MEDIUMCVSS 6.1fixed in 12.112026-04-14
CVE-2026-34614 [MEDIUM] CWE-79 CVE-2026-34614: Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (X Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Scope is changed.
nvd
CVE-2024-54039P4MEDIUMCVSS 5.4fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-54039 [MEDIUM] CWE-79 CVE-2024-54039: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-54040P4MEDIUMCVSS 5.4fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-54040 [MEDIUM] CWE-79 CVE-2024-54040: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-54041P4MEDIUMCVSS 5.4fixed in 11.4.9≥ 12.0, < 12.72024-12-10
CVE-2024-54041 [MEDIUM] CWE-79 CVE-2024-54041: Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2017-3102P4MEDIUMCVSS 6.1≤ 9.6.12017-07-17
CVE-2017-3102 [MEDIUM] CWE-79 CVE-2017-3102: Adobe Connect versions 9.6.1 and earlier have a reflected cross-site scripting vulnerability. Succes Adobe Connect versions 9.6.1 and earlier have a reflected cross-site scripting vulnerability. Successful exploitation could lead to a reflected cross-site scripting attack.
nvd
Adobe Connect vulnerabilities | cvebase