Adobe Experience Manager vulnerabilities
1,269 known vulnerabilities affecting adobe/experience_manager.
Total CVEs
1,269
CISA KEV
0
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL15HIGH30MEDIUM1213LOW11
Vulnerabilities
Page 5 of 64
CVE-2026-47949P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47949 [MEDIUM] CWE-79 CVE-2026-47949: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47973P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47973 [MEDIUM] CWE-79 CVE-2026-47973: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47977P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47977 [MEDIUM] CWE-79 CVE-2026-47977: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47981P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47981 [MEDIUM] CWE-79 CVE-2026-47981: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47953P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47953 [MEDIUM] CWE-79 CVE-2026-47953: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47943P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47943 [MEDIUM] CWE-79 CVE-2026-47943: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47970P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47970 [MEDIUM] CWE-79 CVE-2026-47970: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-48297P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-48297 [MEDIUM] CWE-79 CVE-2026-48297: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-48299P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-48299 [MEDIUM] CWE-79 CVE-2026-48299: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47958P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47958 [MEDIUM] CWE-79 CVE-2026-47958: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47972P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47972 [MEDIUM] CWE-79 CVE-2026-47972: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47956P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47956 [MEDIUM] CWE-79 CVE-2026-47956: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47950P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47950 [MEDIUM] CWE-79 CVE-2026-47950: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47942P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47942 [MEDIUM] CWE-79 CVE-2026-47942: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47944P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47944 [MEDIUM] CWE-79 CVE-2026-47944: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-48300P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-48300 [MEDIUM] CWE-79 CVE-2026-48300: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-27228P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27228 [MEDIUM] CWE-79 CVE-2026-27228: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27233P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27233 [MEDIUM] CWE-79 CVE-2026-27233: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27256P4MEDIUMCVSS 5.4fixed in 6.5.24fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27256 [MEDIUM] CWE-79 CVE-2026-27256: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27236P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27236 [MEDIUM] CWE-79 CVE-2026-27236: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd