cbcvebase.

Adobe Experience Manager vulnerabilities

1,165 known vulnerabilities affecting adobe/experience_manager.

Total CVEs
1,165
CISA KEV
0
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL13HIGH29MEDIUM1113LOW10

Vulnerabilities

Page 15 of 59
CVE-2024-43749P4MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-43749 [MEDIUM] CWE-79 CVE-2024-43749: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-43742P4MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-43742 [MEDIUM] CWE-79 CVE-2024-43742: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-43728P4MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-43728 [MEDIUM] CWE-79 CVE-2024-43728: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-43746P4MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-43746 [MEDIUM] CWE-79 CVE-2024-43746: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-43744P4MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-43744 [MEDIUM] CWE-79 CVE-2024-43744: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-43747P4MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-43747 [MEDIUM] CWE-79 CVE-2024-43747: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-43739P4MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-43739 [MEDIUM] CWE-79 CVE-2024-43739: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26123P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-26123 [MEDIUM] CWE-79 CVE-2024-26123: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26078P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-26078 [MEDIUM] CWE-79 CVE-2024-26078: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26082P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-26082 [MEDIUM] CWE-79 CVE-2024-26082: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36142P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-36142 [MEDIUM] CWE-79 CVE-2024-36142: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36144P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-36144 [MEDIUM] CWE-79 CVE-2024-36144: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26121P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-26121 [MEDIUM] CWE-79 CVE-2024-26121: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-34120P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-34120 [MEDIUM] CWE-79 CVE-2024-34120: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-34119P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-34119 [MEDIUM] CWE-79 CVE-2024-34119: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36143P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-36143 [MEDIUM] CWE-79 CVE-2024-36143: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26085P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-26085 [MEDIUM] CWE-79 CVE-2024-26085: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48616P4MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48616 [MEDIUM] CWE-79 CVE-2023-48616: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48538P4MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48538 [MEDIUM] CWE-79 CVE-2023-48538: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48588P4MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48588 [MEDIUM] CWE-79 CVE-2023-48588: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
Adobe Experience Manager vulnerabilities | cvebase