cbcvebase.

Adobe Experience Manager vulnerabilities

1,165 known vulnerabilities affecting adobe/experience_manager.

Total CVEs
1,165
CISA KEV
0
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL13HIGH29MEDIUM1113LOW10

Vulnerabilities

Page 1 of 59
CVE-2025-49533P1CRITICALCVSS 9.8ExploitedPoC≤ 6.5.23.02025-07-08
CVE-2025-49533 [CRITICAL] CWE-502 CVE-2025-49533: Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Unt Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction. Scope is unchanged.
nvd
CVE-2025-54249P1MEDIUMCVSS 6.5ExploitedPoC≤ 6.5.23.0≤ 2025.8.0+1 more2025-09-09
CVE-2025-54249 [MEDIUM] CWE-918 CVE-2025-54249: Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a Server-Side Request Forgery Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to manipulate server-side requests and bypass security controls allowing unauthorized read access.
nvd
CVE-2025-54251P2MEDIUMCVSS 4.3ExploitedPoC≤ 6.5.23.0≤ 2025.8.0+1 more2025-09-09
CVE-2025-54251 [MEDIUM] CWE-91 CVE-2025-54251: Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an XML Injection vulnerabilit Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an XML Injection vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to manipulate XML queries and gain limited unauthorized write access.
nvd
CVE-2016-0957P2HIGHCVSS 7.5PoCv5.6.1v6.0.0+1 more2016-02-10
CVE-2016-0957 [HIGH] CVE-2016-0957: Dispatcher before 4.1.5 in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 does not properly implem Dispatcher before 4.1.5 in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 does not properly implement a URL filter, which allows remote attackers to bypass dispatcher rules via unspecified vectors.
nvd
CVE-2016-0956P2HIGHCVSS 7.5PoCv5.6.1v6.0.0+1 more2016-02-10
CVE-2016-0956 [HIGH] CWE-200 CVE-2016-0956: The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2019-8086P2HIGHCVSS 7.5PoCv6.2v6.3+2 more2019-10-25
CVE-2019-8086 [HIGH] CWE-611 CVE-2019-8086: Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnera Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
nvd
CVE-2019-16469P2HIGHCVSS 7.5PoC≥ 6.5.0, < 6.5.3.02020-01-15
CVE-2019-16469 [HIGH] CWE-917 CVE-2019-16469: Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an expression language injec Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an expression language injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
nvd
CVE-2026-48259P2CRITICALCVSS 9.6≤ 6.5.25.0≤ 2020.5.0+3 more2026-07-14
CVE-2026-48259 [CRITICAL] CWE-918 CVE-2026-48259: Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that coul Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could leverage this vulnerability to issue unauthorized server-side requests, potentially gaining elevated access or control over the victim's account
nvd
CVE-2026-48359P2CRITICALCVSS 9.6≤ 6.5.25.0≤ 2020.5.0+3 more2026-07-14
CVE-2026-48359 [CRITICAL] CWE-611 CVE-2026-48359: Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('X Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to read sensitive files, potentially gaining elevated access or control over the victim's
nvd
CVE-2019-7964P2CRITICALCVSS 9.8v6.4v6.52019-08-16
CVE-2019-7964 [CRITICAL] CVE-2019-7964: Adobe Experience Manager versions 6.5, and 6.4 have an authentication bypass vulnerability. Successf Adobe Experience Manager versions 6.5, and 6.4 have an authentication bypass vulnerability. Successful exploitation could lead to remote code execution.
nvd
CVE-2018-5006P3HIGHCVSS 7.5≤ 6.4.02018-07-20
CVE-2018-5006 [HIGH] CWE-918 CVE-2018-5006: Adobe Experience Manager versions 6.4 and earlier have a Server-Side Request Forgery vulnerability. Adobe Experience Manager versions 6.4 and earlier have a Server-Side Request Forgery vulnerability. Successful exploitation could lead to sensitive information disclosure.
nvd
CVE-2021-40722P2CRITICALCVSS 9.8≤ 6.5.10.0≥ unspecified, ≤ 6.5.10.02022-01-13
CVE-2021-40722 [CRITICAL] CWE-611 CVE-2021-40722: AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML Ext AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) injection vulnerability that could be abused by an attacker to achieve RCE.
nvd
CVE-2024-26029P3CRITICALCVSS 9.8fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-26029 [CRITICAL] CWE-284 CVE-2024-26029: Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Access Control vuln Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain disclose information. Exploitation of this issue does not require user interaction.
nvd
CVE-2019-8088P3CRITICALCVSS 9.8v6.2v6.3+2 more2019-10-25
CVE-2019-8088 [CRITICAL] CWE-77 CVE-2019-8088: Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Succ Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2026-48252P3HIGHCVSS 8.6≤ 6.5.25.0≤ 2020.5.0+3 more2026-07-14
CVE-2026-48252 [HIGH] CWE-306 CVE-2026-48252: Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction. Scope is changed.
nvd
CVE-2017-3108P3CRITICALCVSS 9.8≤ 6.22017-08-11
CVE-2017-3108 [CRITICAL] CWE-434 CVE-2017-3108: Adobe Experience Manager 6.2 and earlier has a malicious file execution vulnerability. Adobe Experience Manager 6.2 and earlier has a malicious file execution vulnerability.
nvd
CVE-2025-54248P3HIGHCVSS 7.7≤ 6.5.23.0≤ 2025.8.0+1 more2025-09-09
CVE-2025-54248 [HIGH] CWE-20 CVE-2025-54248: Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Scope is changed
nvd
CVE-2026-48310P3HIGHCVSS 8.6≤ 6.5.25.0≤ 2020.5.0+3 more2026-07-14
CVE-2026-48310 [HIGH] CWE-22 CVE-2026-48310: Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directo Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user
nvd
CVE-2025-46840P3HIGHCVSS 8.7fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46840 [HIGH] CWE-285 CVE-2025-46840: Adobe Experience Manager versions 6.5.22 and earlier are affected by an Improper Authorization vulne Adobe Experience Manager versions 6.5.22 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. A low privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue requires user interaction. A successful attacker can abu
nvd
CVE-2021-28627P3HIGHCVSS 8.8≤ 6.5.8.0≥ unspecified, ≤ 6.5.8.02021-08-24
CVE-2021-28627 [HIGH] CWE-918 CVE-2021-28627: Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by a Server-side Request Forgery. An authenticated attacker could leverage this vulnerability to contact systems blocked by the dispatcher. Exploitation of this issue does not require user interaction.
nvd
1 / 59Next →
Adobe Experience Manager vulnerabilities | cvebase