Adobe Experience Manager vulnerabilities
1,165 known vulnerabilities affecting adobe/experience_manager.
Total CVEs
1,165
CISA KEV
0
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL13HIGH30MEDIUM1112LOW10
Vulnerabilities
Page 42 of 59
CVE-2026-47935P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47935 [MEDIUM] CWE-79 CVE-2026-47935: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based C
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a
nvd
CVE-2026-34692P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-34692 [MEDIUM] CWE-79 CVE-2026-34692: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based C
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a
nvd
CVE-2026-47989P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47989 [MEDIUM] CWE-79 CVE-2026-47989: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based C
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a
nvd
CVE-2026-47986P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47986 [MEDIUM] CWE-79 CVE-2026-47986: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based C
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a
nvd
CVE-2026-47985P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47985 [MEDIUM] CWE-79 CVE-2026-47985: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based C
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a
nvd
CVE-2026-48264P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-48264 [MEDIUM] CWE-79 CVE-2026-48264: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based C
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a
nvd
CVE-2026-48250P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-48250 [MEDIUM] CWE-79 CVE-2026-48250: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based C
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a
nvd
CVE-2026-48268P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-48268 [MEDIUM] CWE-79 CVE-2026-48268: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based C
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a
nvd
CVE-2026-47987P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47987 [MEDIUM] CWE-79 CVE-2026-47987: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based C
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a
nvd
CVE-2026-48256P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-48256 [MEDIUM] CWE-79 CVE-2026-48256: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based C
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a
nvd
CVE-2026-47982P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47982 [MEDIUM] CWE-79 CVE-2026-47982: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based C
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a
nvd
CVE-2026-48260P4MEDIUMCVSS 5.4≤ 6.5.25.0≤ 2020.5.0+3 more2026-07-14
CVE-2026-48260 [MEDIUM] CWE-79 CVE-2026-48260: Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An att
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is
nvd
CVE-2026-48255P4MEDIUMCVSS 5.4≤ 6.5.25.0≤ 2020.5.0+3 more2026-07-14
CVE-2026-48255 [MEDIUM] CWE-79 CVE-2026-48255: Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An att
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is
nvd
CVE-2026-48261P4MEDIUMCVSS 5.4≤ 6.5.25.0≤ 2020.5.0+3 more2026-07-14
CVE-2026-48261 [MEDIUM] CWE-79 CVE-2026-48261: Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An att
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is
nvd
CVE-2026-48262P4MEDIUMCVSS 5.4≤ 6.5.25.0≤ 2020.5.0+3 more2026-07-14
CVE-2026-48262 [MEDIUM] CWE-79 CVE-2026-48262: Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An att
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is
nvd
CVE-2026-48254P4MEDIUMCVSS 5.4≤ 6.5.25.0≤ 2020.5.0+3 more2026-07-14
CVE-2026-48254 [MEDIUM] CWE-79 CVE-2026-48254: Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An att
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is
nvd
CVE-2026-48253P4MEDIUMCVSS 5.4≤ 6.5.25.0≤ 2020.5.0+3 more2026-07-14
CVE-2026-48253 [MEDIUM] CWE-79 CVE-2026-48253: Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An att
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is
nvd
CVE-2026-48257P4MEDIUMCVSS 5.4≤ 6.5.25.0≤ 2020.5.0+3 more2026-07-14
CVE-2026-48257 [MEDIUM] CWE-79 CVE-2026-48257: Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An att
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is
nvd
CVE-2018-5005P4MEDIUMCVSS 6.1≥ 6.3.2.1, ≤ 6.3.2.2v6.4+1 more2018-09-06
CVE-2018-5005 [MEDIUM] CWE-79 CVE-2018-5005: Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a Cross-site Scripting vulnerabil
Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a Cross-site Scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
nvd
CVE-2018-12806P4MEDIUMCVSS 6.1≥ 6.1.2.1, ≤ 6.1.2.16≥ 6.2.1.1, ≤ 6.2.1.152018-08-29
CVE-2018-12806 [MEDIUM] CWE-79 CVE-2018-12806: Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting
Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
nvd