Adobe Experience Manager vulnerabilities

1,088 known vulnerabilities affecting adobe/experience_manager.

Total CVEs
1,088
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH27MEDIUM1042LOW8

Vulnerabilities

Page 10 of 55
CVE-2025-46984MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46984 [MEDIUM] CWE-79 CVE-2025-46984: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46918MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46918 [MEDIUM] CWE-79 CVE-2025-46918: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46844MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46844 [MEDIUM] CWE-79 CVE-2025-46844: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47074MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47074 [MEDIUM] CWE-79 CVE-2025-47074: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46879MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46879 [MEDIUM] CWE-79 CVE-2025-46879: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46891MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46891 [MEDIUM] CWE-79 CVE-2025-46891: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47093MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47093 [MEDIUM] CWE-79 CVE-2025-47093: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46865MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46865 [MEDIUM] CWE-79 CVE-2025-46865: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46877MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46877 [MEDIUM] CWE-79 CVE-2025-46877: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47052MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47052 [MEDIUM] CWE-79 CVE-2025-47052: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46850MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46850 [MEDIUM] CWE-79 CVE-2025-46850: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46986MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46986 [MEDIUM] CWE-79 CVE-2025-46986: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46949MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46949 [MEDIUM] CWE-79 CVE-2025-46949: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47005MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47005 [MEDIUM] CWE-79 CVE-2025-47005: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46985MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46985 [MEDIUM] CWE-79 CVE-2025-46985: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46895MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46895 [MEDIUM] CWE-79 CVE-2025-46895: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46951MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46951 [MEDIUM] CWE-79 CVE-2025-46951: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46952MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46952 [MEDIUM] CWE-79 CVE-2025-46952: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46874MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46874 [MEDIUM] CWE-79 CVE-2025-46874: Adobe Experience Manager versions 6.5.22 and earlier are affected by a reflected Cross-Site Scriptin Adobe Experience Manager versions 6.5.22 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2025-46988MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46988 [MEDIUM] CWE-79 CVE-2025-46988: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd