Adobe Experience Manager vulnerabilities
1,269 known vulnerabilities affecting adobe/experience_manager.
Total CVEs
1,269
CISA KEV
0
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL15HIGH30MEDIUM1213LOW11
Vulnerabilities
Page 4 of 64
CVE-2019-7953P4MEDIUMCVSS 6.5≥ 6.0, ≤ 6.42019-07-18
CVE-2019-7953 [MEDIUM] CWE-352 CVE-2019-7953: Adobe Experience Manager version 6.4 and ealier have a Cross-Site Request Forgery vulnerability. Suc
Adobe Experience Manager version 6.4 and ealier have a Cross-Site Request Forgery vulnerability. Successful exploitation could lead to Sensitive Information disclosure in the context of the current user.
nvd
CVE-2019-8234P4MEDIUMCVSS 6.5v6.2v6.3+1 more2019-10-25
CVE-2019-8234 [MEDIUM] CWE-352 CVE-2019-8234: Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a cross-site request forgery vulnerability.
Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a cross-site request forgery vulnerability. Successful exploitation could lead to sensitive information disclosure.
nvd
CVE-2021-40713P4MEDIUMCVSS 5.9≤ 6.5.9.0≥ unspecified, ≤ 6.5.9.02021-09-27
CVE-2021-40713 [MEDIUM] CWE-295 CVE-2021-40713: Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a improper certificate validat
Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a improper certificate validation vulnerability in the cold storage component. If an attacker can achieve a man in the middle when the cold server establishes a new certificate, they would be able to harvest sensitive information.
nvd
CVE-2026-47990P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47990 [MEDIUM] CWE-79 CVE-2026-47990: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47941P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47941 [MEDIUM] CWE-79 CVE-2026-47941: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-48304P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-48304 [MEDIUM] CWE-79 CVE-2026-48304: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47936P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47936 [MEDIUM] CWE-79 CVE-2026-47936: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47974P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47974 [MEDIUM] CWE-79 CVE-2026-47974: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47978P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47978 [MEDIUM] CWE-79 CVE-2026-47978: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-48301P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-48301 [MEDIUM] CWE-79 CVE-2026-48301: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47939P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47939 [MEDIUM] CWE-79 CVE-2026-47939: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47966P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47966 [MEDIUM] CWE-79 CVE-2026-47966: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47951P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47951 [MEDIUM] CWE-79 CVE-2026-47951: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47975P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47975 [MEDIUM] CWE-79 CVE-2026-47975: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47962P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47962 [MEDIUM] CWE-79 CVE-2026-47962: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47957P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47957 [MEDIUM] CWE-79 CVE-2026-47957: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47948P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47948 [MEDIUM] CWE-79 CVE-2026-47948: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47954P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47954 [MEDIUM] CWE-79 CVE-2026-47954: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47945P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47945 [MEDIUM] CWE-79 CVE-2026-47945: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47980P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47980 [MEDIUM] CWE-79 CVE-2026-47980: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd