Adobe Experience Manager vulnerabilities
1,165 known vulnerabilities affecting adobe/experience_manager.
Total CVEs
1,165
CISA KEV
0
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL13HIGH29MEDIUM1113LOW10
Vulnerabilities
Page 23 of 59
CVE-2025-47004P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47004 [MEDIUM] CWE-79 CVE-2025-47004: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46984P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46984 [MEDIUM] CWE-79 CVE-2025-46984: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47052P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47052 [MEDIUM] CWE-79 CVE-2025-47052: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46986P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46986 [MEDIUM] CWE-79 CVE-2025-46986: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46988P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46988 [MEDIUM] CWE-79 CVE-2025-46988: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47041P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47041 [MEDIUM] CWE-79 CVE-2025-47041: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47036P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47036 [MEDIUM] CWE-79 CVE-2025-47036: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47029P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47029 [MEDIUM] CWE-79 CVE-2025-47029: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46999P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46999 [MEDIUM] CWE-79 CVE-2025-46999: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47027P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47027 [MEDIUM] CWE-79 CVE-2025-47027: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47039P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47039 [MEDIUM] CWE-79 CVE-2025-47039: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46990P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46990 [MEDIUM] CWE-79 CVE-2025-46990: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47066P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47066 [MEDIUM] CWE-79 CVE-2025-47066: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47037P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47037 [MEDIUM] CWE-79 CVE-2025-47037: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47047P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47047 [MEDIUM] CWE-79 CVE-2025-47047: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47007P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47007 [MEDIUM] CWE-79 CVE-2025-47007: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47038P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47038 [MEDIUM] CWE-79 CVE-2025-47038: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46992P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46992 [MEDIUM] CWE-79 CVE-2025-46992: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47010P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47010 [MEDIUM] CWE-79 CVE-2025-47010: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47013P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47013 [MEDIUM] CWE-79 CVE-2025-47013: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd