Adobe Experience Manager vulnerabilities
1,165 known vulnerabilities affecting adobe/experience_manager.
Total CVEs
1,165
CISA KEV
0
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL13HIGH29MEDIUM1113LOW10
Vulnerabilities
Page 13 of 59
CVE-2021-44177P4MEDIUMCVSS 6.1≤ 6.5.10.0≥ unspecified, ≤ 6.5.10.02022-01-13
CVE-2021-44177 [MEDIUM] CWE-79 CVE-2021-44177: AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross
AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2021-44176P4MEDIUMCVSS 6.1≤ 6.5.10.0≥ unspecified, ≤ 6.5.10.02022-01-13
CVE-2021-44176 [MEDIUM] CWE-79 CVE-2021-44176: AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross
AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2020-9741P4MEDIUMCVSS 5.4≥ 6.4.0.0, ≤ 6.4.8.2≥ 6.5.0.0, ≤ 6.5.5.0+1 more2020-09-10
CVE-2020-9741 [MEDIUM] CWE-79 CVE-2020-9741: The AEM forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) is affected by a store
The AEM forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) is affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Forms component. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.
nvd
CVE-2020-9740P4MEDIUMCVSS 5.4≥ 6.3.0.0, ≤ 6.3.3.8≥ 6.4.0.0, ≤ 6.4.8.1+3 more2020-09-10
CVE-2020-9740 [MEDIUM] CWE-79 CVE-2020-9740: AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and be
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Design Importer. These scripts may be executed in a victim’s browser when they open the page containing th
nvd
CVE-2020-9734P4MEDIUMCVSS 5.4≥ 6.4.0.0, ≤ 6.4.8.1≥ 6.5.0.0, ≤ 6.5.5.0+1 more2020-09-10
CVE-2020-9734 [MEDIUM] CWE-79 CVE-2020-9734: The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.1 (and below) is affected by a store
The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.1 (and below) is affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Forms component. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.
nvd
CVE-2020-9742P4MEDIUMCVSS 5.4≥ 6.3.0.0, ≤ 6.3.3.8≥ 6.4.0.0, ≤ 6.4.8.1+2 more2020-09-10
CVE-2020-9742 [MEDIUM] CWE-79 CVE-2020-9742: AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below) and 6.3.3.8 (and below) are affected by a stor
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below) and 6.3.3.8 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Inbox calendar feature. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.
nvd
CVE-2021-40711P4MEDIUMCVSS 5.4≤ 6.5.9.0≥ unspecified, ≤ 6.5.9.02021-09-27
CVE-2021-40711 [MEDIUM] CWE-79 CVE-2021-40711: Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a stored XSS vulnerability whe
Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a stored XSS vulnerability when creating Content Fragments. An authenticated attacker can send a malformed POST request to achieve arbitrary code execution. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36141P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-36141 [MEDIUM] CWE-79 CVE-2024-36141: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26092P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-26092 [MEDIUM] CWE-79 CVE-2024-26092: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26054P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-26054 [MEDIUM] CWE-79 CVE-2024-26054: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26081P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-26081 [MEDIUM] CWE-79 CVE-2024-26081: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36150P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-36150 [MEDIUM] CWE-79 CVE-2024-36150: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36168P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-36168 [MEDIUM] CWE-79 CVE-2024-36168: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36154P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-36154 [MEDIUM] CWE-79 CVE-2024-36154: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36170P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-36170 [MEDIUM] CWE-79 CVE-2024-36170: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-20769P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-20769 [MEDIUM] CWE-79 CVE-2024-20769: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36156P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-36156 [MEDIUM] CWE-79 CVE-2024-36156: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26095P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-26095 [MEDIUM] CWE-79 CVE-2024-26095: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36149P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-36149 [MEDIUM] CWE-79 CVE-2024-36149: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36157P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-36157 [MEDIUM] CWE-79 CVE-2024-36157: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd