Adobe Experience Manager vulnerabilities
1,088 known vulnerabilities affecting adobe/experience_manager.
Total CVEs
1,088
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH27MEDIUM1042LOW8
Vulnerabilities
Page 43 of 55
CVE-2023-48513MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48513 [MEDIUM] CWE-79 CVE-2023-48513: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48546MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48546 [MEDIUM] CWE-79 CVE-2023-48546: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48621MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48621 [MEDIUM] CWE-79 CVE-2023-48621: Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scriptin
Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48596MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48596 [MEDIUM] CWE-79 CVE-2023-48596: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48559MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48559 [MEDIUM] CWE-79 CVE-2023-48559: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48599MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48599 [MEDIUM] CWE-79 CVE-2023-48599: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48540MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48540 [MEDIUM] CWE-79 CVE-2023-48540: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48556MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48556 [MEDIUM] CWE-79 CVE-2023-48556: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48463MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48463 [MEDIUM] CWE-79 CVE-2023-48463: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48472MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48472 [MEDIUM] CWE-79 CVE-2023-48472: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48461MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48461 [MEDIUM] CWE-79 CVE-2023-48461: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48453MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48453 [MEDIUM] CWE-79 CVE-2023-48453: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48583MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48583 [MEDIUM] CWE-79 CVE-2023-48583: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48521MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48521 [MEDIUM] CWE-79 CVE-2023-48521: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48470MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48470 [MEDIUM] CWE-79 CVE-2023-48470: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48474MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48474 [MEDIUM] CWE-79 CVE-2023-48474: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48578MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48578 [MEDIUM] CWE-79 CVE-2023-48578: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48448MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48448 [MEDIUM] CWE-79 CVE-2023-48448: Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scriptin
Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48485MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48485 [MEDIUM] CWE-79 CVE-2023-48485: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48483MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48483 [MEDIUM] CWE-79 CVE-2023-48483: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd