Adobe Experience Manager vulnerabilities
1,269 known vulnerabilities affecting adobe/experience_manager.
Total CVEs
1,269
CISA KEV
0
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL15HIGH30MEDIUM1213LOW11
Vulnerabilities
Page 14 of 64
CVE-2025-64547P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2025.12.0+1 more2025-12-10
CVE-2025-64547 [MEDIUM] CWE-79 CVE-2025-64547: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-64827P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2025.12.0+1 more2025-12-10
CVE-2025-64827 [MEDIUM] CWE-79 CVE-2025-64827: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2018-4875P4MEDIUMCVSS 6.1v6.0.0v6.1.02018-02-27
CVE-2018-4875 [MEDIUM] CWE-79 CVE-2018-4875: Adobe Experience Manager versions 6.1 and 6.0 are vulnerable to a reflected cross-site scripting vul
Adobe Experience Manager versions 6.1 and 6.0 are vulnerable to a reflected cross-site scripting vulnerability related to the handling of malicious content embedded in image files uploaded to the DAM.
nvd
CVE-2021-21084P4MEDIUMCVSS 6.1≤ 6.3.3.8≥ 6.4.0.0, < 6.4.8.4+2 more2021-06-28
CVE-2021-21084 [MEDIUM] CWE-79 CVE-2021-21084: AEM's Cloud Service offering, as well as versions 6.5.7.0 (and below), 6.4.8.3 (and below) and 6.3.3
AEM's Cloud Service offering, as well as versions 6.5.7.0 (and below), 6.4.8.3 (and below) and 6.3.3.8 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to
nvd
CVE-2021-43765P4MEDIUMCVSS 6.1≤ 6.5.10.0≥ unspecified, ≤ 6.5.10.02022-01-13
CVE-2021-43765 [MEDIUM] CWE-79 CVE-2021-43765: AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross
AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2021-44177P4MEDIUMCVSS 6.1≤ 6.5.10.0≥ unspecified, ≤ 6.5.10.02022-01-13
CVE-2021-44177 [MEDIUM] CWE-79 CVE-2021-44177: AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross
AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2021-44176P4MEDIUMCVSS 6.1≤ 6.5.10.0≥ unspecified, ≤ 6.5.10.02022-01-13
CVE-2021-44176 [MEDIUM] CWE-79 CVE-2021-44176: AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross
AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2020-9741P4MEDIUMCVSS 5.4≥ 6.4.0.0, ≤ 6.4.8.2≥ 6.5.0.0, ≤ 6.5.5.0+1 more2020-09-10
CVE-2020-9741 [MEDIUM] CWE-79 CVE-2020-9741: The AEM forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) is affected by a store
The AEM forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) is affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Forms component. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.
nvd
CVE-2020-9740P4MEDIUMCVSS 5.4≥ 6.3.0.0, ≤ 6.3.3.8≥ 6.4.0.0, ≤ 6.4.8.1+3 more2020-09-10
CVE-2020-9740 [MEDIUM] CWE-79 CVE-2020-9740: AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and be
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Design Importer. These scripts may be executed in a victim’s browser when they open the page containing th
nvd
CVE-2020-9734P4MEDIUMCVSS 5.4≥ 6.4.0.0, ≤ 6.4.8.1≥ 6.5.0.0, ≤ 6.5.5.0+1 more2020-09-10
CVE-2020-9734 [MEDIUM] CWE-79 CVE-2020-9734: The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.1 (and below) is affected by a store
The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.1 (and below) is affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Forms component. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.
nvd
CVE-2020-9742P4MEDIUMCVSS 5.4≥ 6.3.0.0, ≤ 6.3.3.8≥ 6.4.0.0, ≤ 6.4.8.1+2 more2020-09-10
CVE-2020-9742 [MEDIUM] CWE-79 CVE-2020-9742: AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below) and 6.3.3.8 (and below) are affected by a stor
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below) and 6.3.3.8 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Inbox calendar feature. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.
nvd
CVE-2021-43764P4MEDIUMCVSS 5.4≤ 6.5.10.0≥ unspecified, ≤ 6.5.10.02022-01-13
CVE-2021-43764 [MEDIUM] CWE-79 CVE-2021-43764: AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross
AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2021-40711P4MEDIUMCVSS 5.4≤ 6.5.9.0≥ unspecified, ≤ 6.5.9.02021-09-27
CVE-2021-40711 [MEDIUM] CWE-79 CVE-2021-40711: Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a stored XSS vulnerability whe
Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a stored XSS vulnerability when creating Content Fragments. An authenticated attacker can send a malformed POST request to achieve arbitrary code execution. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36141P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-36141 [MEDIUM] CWE-79 CVE-2024-36141: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26092P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-26092 [MEDIUM] CWE-79 CVE-2024-26092: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26054P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-26054 [MEDIUM] CWE-79 CVE-2024-26054: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26081P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-26081 [MEDIUM] CWE-79 CVE-2024-26081: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36150P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-36150 [MEDIUM] CWE-79 CVE-2024-36150: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36168P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-36168 [MEDIUM] CWE-79 CVE-2024-36168: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36154P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-36154 [MEDIUM] CWE-79 CVE-2024-36154: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd