cbcvebase.

Adobe Experience Manager vulnerabilities

1,269 known vulnerabilities affecting adobe/experience_manager.

Total CVEs
1,269
CISA KEV
0
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL15HIGH30MEDIUM1213LOW11

Vulnerabilities

Page 24 of 64
CVE-2024-53960P4MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-53960 [MEDIUM] CWE-79 CVE-2024-53960: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-52992P4MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-52992 [MEDIUM] CWE-79 CVE-2024-52992: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-52991P4MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-52991 [MEDIUM] CWE-79 CVE-2024-52991: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-52865P4MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-52865 [MEDIUM] CWE-79 CVE-2024-52865: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-52858P4MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-52858 [MEDIUM] CWE-79 CVE-2024-52858: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-52993P4MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-52993 [MEDIUM] CWE-79 CVE-2024-52993: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-52859P4MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-52859 [MEDIUM] CWE-79 CVE-2024-52859: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-52864P4MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-52864 [MEDIUM] CWE-79 CVE-2024-52864: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-52861P4MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-52861 [MEDIUM] CWE-79 CVE-2024-52861: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-52862P4MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-52862 [MEDIUM] CWE-79 CVE-2024-52862: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-52857P4MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-52857 [MEDIUM] CWE-79 CVE-2024-52857: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-53964P4MEDIUMCVSS 5.4fixed in 6.5.22fixed in 2024.11.02025-02-05
CVE-2024-53964 [MEDIUM] CWE-79 CVE-2024-53964: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-53966P4MEDIUMCVSS 5.4fixed in 6.5.22fixed in 2024.11.02025-02-05
CVE-2024-53966 [MEDIUM] CWE-79 CVE-2024-53966: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-53962P4MEDIUMCVSS 5.4fixed in 6.5.22fixed in 2024.11.02025-02-05
CVE-2024-53962 [MEDIUM] CWE-79 CVE-2024-53962: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-51464P4MEDIUMCVSS 5.4≤ 6.5.182024-01-18
CVE-2023-51464 [MEDIUM] CWE-79 CVE-2023-51464: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-51460P4MEDIUMCVSS 5.4≤ 6.5.18.0fixed in 2023.11.02023-12-20
CVE-2023-51460 [MEDIUM] CWE-79 CVE-2023-51460: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-51457P4MEDIUMCVSS 5.4≤ 6.5.18.0fixed in 2023.11.02023-12-20
CVE-2023-51457 [MEDIUM] CWE-79 CVE-2023-51457: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-51461P4MEDIUMCVSS 5.4≤ 6.5.18.0fixed in 2023.11.02023-12-20
CVE-2023-51461 [MEDIUM] CWE-79 CVE-2023-51461: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-51458P4MEDIUMCVSS 5.4≤ 6.5.18.0fixed in 2023.11.02023-12-20
CVE-2023-51458 [MEDIUM] CWE-79 CVE-2023-51458: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47092P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47092 [MEDIUM] CWE-79 CVE-2025-47092: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
Adobe Experience Manager vulnerabilities | cvebase