Adobe Experience Manager vulnerabilities
1,088 known vulnerabilities affecting adobe/experience_manager.
Total CVEs
1,088
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH27MEDIUM1042LOW8
Vulnerabilities
Page 46 of 55
CVE-2023-48489MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48489 [MEDIUM] CWE-79 CVE-2023-48489: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48459MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48459 [MEDIUM] CWE-79 CVE-2023-48459: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48571MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48571 [MEDIUM] CWE-79 CVE-2023-48571: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48594MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48594 [MEDIUM] CWE-79 CVE-2023-48594: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48549MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48549 [MEDIUM] CWE-79 CVE-2023-48549: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-47064MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-47064 [MEDIUM] CWE-79 CVE-2023-47064: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48532MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48532 [MEDIUM] CWE-79 CVE-2023-48532: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48446MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48446 [MEDIUM] CWE-79 CVE-2023-48446: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48450MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48450 [MEDIUM] CWE-79 CVE-2023-48450: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48526MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48526 [MEDIUM] CWE-79 CVE-2023-48526: Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scriptin
Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48551MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48551 [MEDIUM] CWE-79 CVE-2023-48551: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48624MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48624 [MEDIUM] CWE-79 CVE-2023-48624: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48602MEDIUMCVSS 5.4≤ 6.5.182023-12-15
CVE-2023-48602 [MEDIUM] CWE-79 CVE-2023-48602: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48544MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48544 [MEDIUM] CWE-79 CVE-2023-48544: Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2023-48525MEDIUMCVSS 5.4≤ 6.5.18.02023-12-15
CVE-2023-48525 [MEDIUM] CWE-79 CVE-2023-48525: Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-bas
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-48608LOWCVSS 3.5≤ 6.5.182023-12-15
CVE-2023-48608 [LOW] CWE-20 CVE-2023-48608: Adobe Experience Manager versions 6.5.18 and earlier are affected by an Improper Input Validation vu
Adobe Experience Manager versions 6.5.18 and earlier are affected by an Improper Input Validation vulnerability. A low-privileged attacker could leverage this vulnerability to achieve a low-integrity impact within the application. Exploitation of this issue requires user interaction.
nvd
CVE-2023-38215MEDIUMCVSS 5.4fixed in 6.5.18.02023-09-13
CVE-2023-38215 [MEDIUM] CWE-79 CVE-2023-38215: Adobe Experience Manager versions 6.5.17 and earlier are affected by a reflected Cross-Site Scriptin
Adobe Experience Manager versions 6.5.17 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-38214MEDIUMCVSS 5.4≤ 6.5.172023-09-13
CVE-2023-38214 [MEDIUM] CWE-79 CVE-2023-38214: Adobe Experience Manager versions 6.5.17 and earlier are affected by a reflected Cross-Site Scriptin
Adobe Experience Manager versions 6.5.17 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-29322MEDIUMCVSS 5.4fixed in 6.5.17.02023-06-15
CVE-2023-29322 [MEDIUM] CWE-79 CVE-2023-29322: Adobe Experience Manager versions 6.5.16.0 (and earlier) is affected by a reflected Cross-Site Scrip
Adobe Experience Manager versions 6.5.16.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-29304MEDIUMCVSS 5.4fixed in 6.5.17.02023-06-15
CVE-2023-29304 [MEDIUM] CWE-79 CVE-2023-29304: Adobe Experience Manager versions 6.5.16.0 (and earlier) is affected by a reflected Cross-Site Scrip
Adobe Experience Manager versions 6.5.16.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd