cbcvebase.

Adobe Experience Manager vulnerabilities

1,165 known vulnerabilities affecting adobe/experience_manager.

Total CVEs
1,165
CISA KEV
0
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL13HIGH29MEDIUM1113LOW10

Vulnerabilities

Page 30 of 59
CVE-2025-47035P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47035 [MEDIUM] CWE-79 CVE-2025-47035: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47011P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47011 [MEDIUM] CWE-79 CVE-2025-47011: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46979P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46979 [MEDIUM] CWE-79 CVE-2025-46979: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46918P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46918 [MEDIUM] CWE-79 CVE-2025-46918: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46895P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46895 [MEDIUM] CWE-79 CVE-2025-46895: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47073P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47073 [MEDIUM] CWE-79 CVE-2025-47073: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46977P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46977 [MEDIUM] CWE-79 CVE-2025-46977: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46972P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46972 [MEDIUM] CWE-79 CVE-2025-46972: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46886P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46886 [MEDIUM] CWE-79 CVE-2025-46886: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46930P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46930 [MEDIUM] CWE-79 CVE-2025-46930: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47072P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47072 [MEDIUM] CWE-79 CVE-2025-47072: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46947P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46947 [MEDIUM] CWE-79 CVE-2025-46947: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46968P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46968 [MEDIUM] CWE-79 CVE-2025-46968: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46899P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46899 [MEDIUM] CWE-79 CVE-2025-46899: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46931P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46931 [MEDIUM] CWE-79 CVE-2025-46931: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47076P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47076 [MEDIUM] CWE-79 CVE-2025-47076: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46970P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46970 [MEDIUM] CWE-79 CVE-2025-46970: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46943P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46943 [MEDIUM] CWE-79 CVE-2025-46943: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46894P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46894 [MEDIUM] CWE-79 CVE-2025-46894: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46963P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46963 [MEDIUM] CWE-79 CVE-2025-46963: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
Adobe Experience Manager vulnerabilities | cvebase