Adobe Experience Manager vulnerabilities
1,088 known vulnerabilities affecting adobe/experience_manager.
Total CVEs
1,088
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH27MEDIUM1042LOW8
Vulnerabilities
Page 45 of 55
CVE-2023-48563MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48563 [MEDIUM] CWE-79 CVE-2023-48563: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48454MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48454 [MEDIUM] CWE-79 CVE-2023-48454: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48585MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48585 [MEDIUM] CWE-79 CVE-2023-48585: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48507MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48507 [MEDIUM] CWE-79 CVE-2023-48507: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48517MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48517 [MEDIUM] CWE-79 CVE-2023-48517: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48536MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48536 [MEDIUM] CWE-79 CVE-2023-48536: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48502MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48502 [MEDIUM] CWE-79 CVE-2023-48502: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48552MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48552 [MEDIUM] CWE-79 CVE-2023-48552: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48603MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48603 [MEDIUM] CWE-79 CVE-2023-48603: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48491MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48491 [MEDIUM] CWE-79 CVE-2023-48491: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48508MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48508 [MEDIUM] CWE-79 CVE-2023-48508: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48444MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48444 [MEDIUM] CWE-79 CVE-2023-48444: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48520MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48520 [MEDIUM] CWE-79 CVE-2023-48520: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48598MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48598 [MEDIUM] CWE-79 CVE-2023-48598: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48449MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48449 [MEDIUM] CWE-79 CVE-2023-48449: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-47065MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-47065 [MEDIUM] CWE-79 CVE-2023-47065: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48486MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48486 [MEDIUM] CWE-79 CVE-2023-48486: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48539MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48539 [MEDIUM] CWE-79 CVE-2023-48539: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48590MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48590 [MEDIUM] CWE-79 CVE-2023-48590: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48618MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48618 [MEDIUM] CWE-79 CVE-2023-48618: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd