Adobe Experience Manager vulnerabilities
1,269 known vulnerabilities affecting adobe/experience_manager.
Total CVEs
1,269
CISA KEV
0
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL15HIGH30MEDIUM1213LOW11
Vulnerabilities
Page 42 of 64
CVE-2024-36189P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-36189 [MEDIUM] CWE-79 CVE-2024-36189: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36192P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-36192 [MEDIUM] CWE-79 CVE-2024-36192: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36191P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-36191 [MEDIUM] CWE-79 CVE-2024-36191: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36196P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-36196 [MEDIUM] CWE-79 CVE-2024-36196: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36198P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-36198 [MEDIUM] CWE-79 CVE-2024-36198: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36193P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-36193 [MEDIUM] CWE-79 CVE-2024-36193: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36199P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-36199 [MEDIUM] CWE-79 CVE-2024-36199: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36209P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-36209 [MEDIUM] CWE-79 CVE-2024-36209: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36195P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-36195 [MEDIUM] CWE-79 CVE-2024-36195: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26076P4MEDIUMCVSS 5.4fixed in 6.5.20.0fixed in 2024.3.02024-04-10
CVE-2024-26076 [MEDIUM] CWE-79 CVE-2024-26076: Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26097P4MEDIUMCVSS 5.4fixed in 6.5.20.0fixed in 2024.3.02024-04-10
CVE-2024-26097 [MEDIUM] CWE-79 CVE-2024-26097: Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26047P4MEDIUMCVSS 5.4fixed in 6.5.20.0fixed in 2024.3.02024-04-10
CVE-2024-26047 [MEDIUM] CWE-79 CVE-2024-26047: Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26098P4MEDIUMCVSS 5.4fixed in 6.5.20.0fixed in 2024.3.02024-04-10
CVE-2024-26098 [MEDIUM] CWE-79 CVE-2024-26098: Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26084P4MEDIUMCVSS 5.4fixed in 6.5.20.0fixed in 2024.3.02024-04-10
CVE-2024-26084 [MEDIUM] CWE-79 CVE-2024-26084: Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-26079P4MEDIUMCVSS 5.4fixed in 6.5.20.0fixed in 2024.3.02024-04-10
CVE-2024-26079 [MEDIUM] CWE-79 CVE-2024-26079: Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-53963P4MEDIUMCVSS 5.4fixed in 6.5.22fixed in 2024.11.02025-02-05
CVE-2024-53963 [MEDIUM] CWE-79 CVE-2024-53963: Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scriptin
Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URL or user input, the attacker can inject malicious sc
nvd
CVE-2024-53965P4MEDIUMCVSS 5.4fixed in 6.5.22fixed in 2024.11.02025-02-05
CVE-2024-53965 [MEDIUM] CWE-79 CVE-2024-53965: Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scriptin
Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URL or user input, the attacker can inject malicious sc
nvd
CVE-2024-36176P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-36176 [MEDIUM] CWE-79 CVE-2024-36176: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36178P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-36178 [MEDIUM] CWE-79 CVE-2024-36178: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-36177P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-36177 [MEDIUM] CWE-79 CVE-2024-36177: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd