Adobe Experience Manager vulnerabilities
1,165 known vulnerabilities affecting adobe/experience_manager.
Total CVEs
1,165
CISA KEV
0
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL13HIGH29MEDIUM1113LOW10
Vulnerabilities
Page 27 of 59
CVE-2025-46929P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46929 [MEDIUM] CWE-79 CVE-2025-46929: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46919P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46919 [MEDIUM] CWE-79 CVE-2025-46919: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46940P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46940 [MEDIUM] CWE-79 CVE-2025-46940: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46974P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46974 [MEDIUM] CWE-79 CVE-2025-46974: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46881P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46881 [MEDIUM] CWE-79 CVE-2025-46881: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46926P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46926 [MEDIUM] CWE-79 CVE-2025-46926: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47077P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47077 [MEDIUM] CWE-79 CVE-2025-47077: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46973P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46973 [MEDIUM] CWE-79 CVE-2025-46973: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47075P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47075 [MEDIUM] CWE-79 CVE-2025-47075: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46964P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46964 [MEDIUM] CWE-79 CVE-2025-46964: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46892P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46892 [MEDIUM] CWE-79 CVE-2025-46892: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-34128P4MEDIUMCVSS 5.4fixed in 6.5.21.0≤ 2024.5.02024-07-23
CVE-2024-34128 [MEDIUM] CWE-79 CVE-2024-34128: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47061P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.52025-07-24
CVE-2025-47061 [MEDIUM] CWE-79 CVE-2025-47061: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46993P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.52025-07-24
CVE-2025-46993 [MEDIUM] CWE-79 CVE-2025-46993: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46996P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.52025-07-24
CVE-2025-46996 [MEDIUM] CWE-79 CVE-2025-46996: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46844P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46844 [MEDIUM] CWE-79 CVE-2025-46844: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-53970P4MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02025-03-19
CVE-2024-53970 [MEDIUM] CWE-79 CVE-2024-53970: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46865P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46865 [MEDIUM] CWE-79 CVE-2025-46865: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46850P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46850 [MEDIUM] CWE-79 CVE-2025-46850: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46949P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46949 [MEDIUM] CWE-79 CVE-2025-46949: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd