Adobe Experience Manager vulnerabilities
1,165 known vulnerabilities affecting adobe/experience_manager.
Total CVEs
1,165
CISA KEV
0
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL13HIGH29MEDIUM1113LOW10
Vulnerabilities
Page 12 of 59
CVE-2026-27249P4MEDIUMCVSS 5.4fixed in 6.5.24fixed in 2026.2.0+1 more2026-03-11
CVE-2026-27249 [MEDIUM] CWE-79 CVE-2026-27249: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27225P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+1 more2026-03-11
CVE-2026-27225 [MEDIUM] CWE-79 CVE-2026-27225: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27255P4MEDIUMCVSS 5.4fixed in 6.5.24fixed in 2026.2.0+1 more2026-03-11
CVE-2026-27255 [MEDIUM] CWE-79 CVE-2026-27255: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27250P4MEDIUMCVSS 5.4fixed in 6.5.24fixed in 2026.2.0+1 more2026-03-11
CVE-2026-27250 [MEDIUM] CWE-79 CVE-2026-27250: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27241P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+1 more2026-03-11
CVE-2026-27241 [MEDIUM] CWE-79 CVE-2026-27241: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27253P4MEDIUMCVSS 5.4fixed in 6.5.24fixed in 2026.2.0+1 more2026-03-11
CVE-2026-27253 [MEDIUM] CWE-79 CVE-2026-27253: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27235P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+1 more2026-03-11
CVE-2026-27235 [MEDIUM] CWE-79 CVE-2026-27235: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27240P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+1 more2026-03-11
CVE-2026-27240 [MEDIUM] CWE-79 CVE-2026-27240: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27248P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+1 more2026-03-11
CVE-2026-27248 [MEDIUM] CWE-79 CVE-2026-27248: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27262P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+1 more2026-03-11
CVE-2026-27262 [MEDIUM] CWE-79 CVE-2026-27262: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27237P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+1 more2026-03-11
CVE-2026-27237 [MEDIUM] CWE-79 CVE-2026-27237: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27232P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+1 more2026-03-11
CVE-2026-27232 [MEDIUM] CWE-79 CVE-2026-27232: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27251P4MEDIUMCVSS 5.4fixed in 6.5.24fixed in 2026.2.0+1 more2026-03-11
CVE-2026-27251 [MEDIUM] CWE-79 CVE-2026-27251: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27223P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+1 more2026-03-11
CVE-2026-27223 [MEDIUM] CWE-79 CVE-2026-27223: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27257P4MEDIUMCVSS 5.4fixed in 6.5.24fixed in 2026.2.0+1 more2026-03-11
CVE-2026-27257 [MEDIUM] CWE-79 CVE-2026-27257: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27242P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+1 more2026-03-11
CVE-2026-27242 [MEDIUM] CWE-79 CVE-2026-27242: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2018-4875P4MEDIUMCVSS 6.1v6.0.0v6.1.02018-02-27
CVE-2018-4875 [MEDIUM] CWE-79 CVE-2018-4875: Adobe Experience Manager versions 6.1 and 6.0 are vulnerable to a reflected cross-site scripting vul
Adobe Experience Manager versions 6.1 and 6.0 are vulnerable to a reflected cross-site scripting vulnerability related to the handling of malicious content embedded in image files uploaded to the DAM.
nvd
CVE-2021-21084P4MEDIUMCVSS 6.1≤ 6.3.3.8≥ 6.4.0.0, < 6.4.8.4+2 more2021-06-28
CVE-2021-21084 [MEDIUM] CWE-79 CVE-2021-21084: AEM's Cloud Service offering, as well as versions 6.5.7.0 (and below), 6.4.8.3 (and below) and 6.3.3
AEM's Cloud Service offering, as well as versions 6.5.7.0 (and below), 6.4.8.3 (and below) and 6.3.3.8 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to
nvd
CVE-2019-8080P4MEDIUMCVSS 6.1v6.3v6.42019-10-24
CVE-2019-8080 [MEDIUM] CWE-79 CVE-2019-8080: Adobe Experience Manager versions 6.4 and 6.3 have a stored cross site scripting vulnerability. Succ
Adobe Experience Manager versions 6.4 and 6.3 have a stored cross site scripting vulnerability. Successful exploitation could lead to privilege escalation.
nvd
CVE-2021-43765P4MEDIUMCVSS 6.1≤ 6.5.10.0≥ unspecified, ≤ 6.5.10.02022-01-13
CVE-2021-43765 [MEDIUM] CWE-79 CVE-2021-43765: AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross
AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd