Adobe Experience Manager vulnerabilities
1,269 known vulnerabilities affecting adobe/experience_manager.
Total CVEs
1,269
CISA KEV
0
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL15HIGH30MEDIUM1213LOW11
Vulnerabilities
Page 39 of 64
CVE-2025-46846P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46846 [MEDIUM] CWE-79 CVE-2025-46846: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46873P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46873 [MEDIUM] CWE-79 CVE-2025-46873: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46878P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46878 [MEDIUM] CWE-79 CVE-2025-46878: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46851P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46851 [MEDIUM] CWE-79 CVE-2025-46851: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46860P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46860 [MEDIUM] CWE-79 CVE-2025-46860: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46866P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46866 [MEDIUM] CWE-79 CVE-2025-46866: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46858P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46858 [MEDIUM] CWE-79 CVE-2025-46858: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-53970P4MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2024.11.02025-03-19
CVE-2024-53970 [MEDIUM] CWE-79 CVE-2024-53970: Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-34128P4MEDIUMCVSS 5.4fixed in 6.5.21.0≤ 2024.5.02024-07-23
CVE-2024-34128 [MEDIUM] CWE-79 CVE-2024-34128: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47085P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47085 [MEDIUM] CWE-79 CVE-2025-47085: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47091P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47091 [MEDIUM] CWE-79 CVE-2025-47091: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47088P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47088 [MEDIUM] CWE-79 CVE-2025-47088: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47084P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47084 [MEDIUM] CWE-79 CVE-2025-47084: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47113P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47113 [MEDIUM] CWE-79 CVE-2025-47113: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47117P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47117 [MEDIUM] CWE-79 CVE-2025-47117: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47083P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47083 [MEDIUM] CWE-79 CVE-2025-47083: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47116P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47116 [MEDIUM] CWE-79 CVE-2025-47116: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47001P4MEDIUMCVSS 5.4fixed in 6.5.22.0fixed in 2025.5.02025-07-30
CVE-2025-47001 [MEDIUM] CWE-79 CVE-2025-47001: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46958P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.5.02025-08-05
CVE-2025-46958 [MEDIUM] CWE-79 CVE-2025-46958: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-47061P4MEDIUMCVSS 5.4fixed in 6.5.23.0fixed in 2025.52025-07-24
CVE-2025-47061 [MEDIUM] CWE-79 CVE-2025-47061: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd