Adobe Experience Manager vulnerabilities
1,088 known vulnerabilities affecting adobe/experience_manager.
Total CVEs
1,088
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH27MEDIUM1042LOW8
Vulnerabilities
Page 21 of 55
CVE-2024-53968MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02025-03-19
CVE-2024-53968 [MEDIUM] CWE-79 CVE-2024-53968: Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scriptin
Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code in the context of the victim's browser session. By manipulating the DOM environment in the victim's browser, a low privileged attacker can inject malicious scripts that are execute
nvd
CVE-2024-53970MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02025-03-19
CVE-2024-53970 [MEDIUM] CWE-79 CVE-2024-53970: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-53967MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02025-03-19
CVE-2024-53967 [MEDIUM] CWE-79 CVE-2024-53967: Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scriptin
Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code in the context of the victim's browser session. By manipulating the DOM environment in the victim's browser, a low privileged attacker can inject malicious scripts that are execute
nvd
CVE-2024-53969MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02025-03-19
CVE-2024-53969 [MEDIUM] CWE-79 CVE-2024-53969: Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scriptin
Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code in the context of the victim's browser session. By manipulating the DOM environment in the victim's browser, a low privileged attacker can inject malicious scripts that are execute
nvd
CVE-2024-53974MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02025-02-19
CVE-2024-53974 [MEDIUM] CWE-79 CVE-2024-53974: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-53963MEDIUMCVSS 5.4fixed in 6.5.22fixed in 2024.11.02025-02-05
CVE-2024-53963 [MEDIUM] CWE-79 CVE-2024-53963: Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scriptin
Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URL or user input, the attacker can inject malicious sc
nvd
CVE-2024-53964MEDIUMCVSS 5.4fixed in 6.5.22fixed in 2024.11.02025-02-05
CVE-2024-53964 [MEDIUM] CWE-79 CVE-2024-53964: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-53965MEDIUMCVSS 5.4fixed in 6.5.22fixed in 2024.11.02025-02-05
CVE-2024-53965 [MEDIUM] CWE-79 CVE-2024-53965: Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scriptin
Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URL or user input, the attacker can inject malicious sc
nvd
CVE-2024-53966MEDIUMCVSS 5.4fixed in 6.5.22fixed in 2024.11.02025-02-05
CVE-2024-53966 [MEDIUM] CWE-79 CVE-2024-53966: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-53962MEDIUMCVSS 5.4fixed in 6.5.22fixed in 2024.11.02025-02-05
CVE-2024-53962 [MEDIUM] CWE-79 CVE-2024-53962: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-43724MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-43724 [MEDIUM] CWE-79 CVE-2024-43724: Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scriptin
Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URL or user input, the attacker can inject malicious scripts that run
nvd
CVE-2024-43740MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-43740 [MEDIUM] CWE-79 CVE-2024-43740: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-43750MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-43750 [MEDIUM] CWE-79 CVE-2024-43750: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-52830MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-52830 [MEDIUM] CWE-79 CVE-2024-52830: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-52842MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-52842 [MEDIUM] CWE-79 CVE-2024-52842: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-43722MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-43722 [MEDIUM] CWE-79 CVE-2024-43722: Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scriptin
Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URL or user input, the attacker can inject malicious scripts that run
nvd
CVE-2024-43735MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-43735 [MEDIUM] CWE-79 CVE-2024-43735: Adobe Experience Manager versions 6.5.21 and earlier are affected by a reflected Cross-Site Scriptin
Adobe Experience Manager versions 6.5.21 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2024-53960MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-53960 [MEDIUM] CWE-79 CVE-2024-53960: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-52849MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-52849 [MEDIUM] CWE-79 CVE-2024-52849: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-52829MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-52829 [MEDIUM] CWE-79 CVE-2024-52829: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd