cbcvebase.

Adobe Experience Manager vulnerabilities

1,165 known vulnerabilities affecting adobe/experience_manager.

Total CVEs
1,165
CISA KEV
0
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL14HIGH30MEDIUM1111LOW10

Vulnerabilities

Page 57 of 59
CVE-2022-38438P4MEDIUMCVSS 5.4fixed in 6.5.14.0≥ unspecified, ≤ 6.5.13.02022-09-23
CVE-2022-38438 [MEDIUM] CWE-79 CVE-2022-38438: Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scrip Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privile
nvd
CVE-2022-30677P4MEDIUMCVSS 5.4≤ 6.5.13.0≥ unspecified, ≤ 6.5.13.02022-09-16
CVE-2022-30677 [MEDIUM] CWE-79 CVE-2022-30677: Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scrip Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privile
nvd
CVE-2022-30678P4MEDIUMCVSS 5.4≤ 6.5.13.0≥ unspecified, ≤ 6.5.13.02022-09-16
CVE-2022-30678 [MEDIUM] CWE-79 CVE-2022-30678: Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scrip Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privile
nvd
CVE-2022-30680P4MEDIUMCVSS 5.4≤ 6.5.13.0≥ unspecified, ≤ 6.5.13.02022-09-16
CVE-2022-30680 [MEDIUM] CWE-79 CVE-2022-30680: Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scrip Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privile
nvd
CVE-2022-30681P4MEDIUMCVSS 5.4≤ 6.5.13.0≥ unspecified, ≤ 6.5.13.02022-09-16
CVE-2022-30681 [MEDIUM] CWE-79 CVE-2022-30681: Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scrip Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privile
nvd
CVE-2022-30684P4MEDIUMCVSS 5.4≤ 6.5.13.0≥ unspecified, ≤ 6.5.13.02022-09-16
CVE-2022-30684 [MEDIUM] CWE-79 CVE-2022-30684: Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scrip Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privile
nvd
CVE-2022-30685P4MEDIUMCVSS 5.4≤ 6.5.13.0≥ unspecified, ≤ 6.5.13.02022-09-16
CVE-2022-30685 [MEDIUM] CWE-79 CVE-2022-30685: Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scrip Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privile
nvd
CVE-2022-34218P4MEDIUMCVSS 5.4≤ 6.5.13.0≥ unspecified, ≤ 6.5.13.02022-09-16
CVE-2022-34218 [MEDIUM] CWE-79 CVE-2022-34218: Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scrip Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privile
nvd
CVE-2022-30686P4MEDIUMCVSS 5.4≤ 6.5.13.0≥ unspecified, ≤ 6.5.13.02022-09-16
CVE-2022-30686 [MEDIUM] CWE-79 CVE-2022-30686: Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scrip Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privile
nvd
CVE-2022-30682P4MEDIUMCVSS 5.4≤ 6.5.13.0≥ unspecified, ≤ 6.5.13.02022-09-16
CVE-2022-30682 [MEDIUM] CWE-79 CVE-2022-30682: Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scrip Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privile
nvd
CVE-2022-35664P4MEDIUMCVSS 5.4≤ 6.5.13.0≥ unspecified, ≤ 6.5.13.02022-09-16
CVE-2022-35664 [MEDIUM] CWE-79 CVE-2022-35664: Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scrip Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privile
nvd
CVE-2022-38439P4MEDIUMCVSS 5.4fixed in 6.5.14.0≥ unspecified, ≤ 6.5.13.02022-09-23
CVE-2022-38439 [MEDIUM] CWE-79 CVE-2022-38439: Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scrip Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privile
nvd
CVE-2023-21615P4MEDIUMCVSS 5.4fixed in 6.5.16.02023-03-22
CVE-2023-21615 [MEDIUM] CWE-79 CVE-2023-21615: Experience Manager versions 6.5.15.0 (and earlier) are affected by a reflected Cross-Site Scripting Experience Manager versions 6.5.15.0 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-21616P4MEDIUMCVSS 5.4fixed in 6.5.16.02023-03-22
CVE-2023-21616 [MEDIUM] CWE-79 CVE-2023-21616: Experience Manager versions 6.5.15.0 (and earlier) are affected by a reflected Cross-Site Scripting Experience Manager versions 6.5.15.0 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-22253P4MEDIUMCVSS 5.4fixed in 6.5.16.0≥ unspecified, ≤ 6.5.15.02023-03-22
CVE-2023-22253 [MEDIUM] CWE-79 CVE-2023-22253: Experience Manager versions 6.5.15.0 (and earlier) are affected by a reflected Cross-Site Scripting Experience Manager versions 6.5.15.0 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-22252P4MEDIUMCVSS 5.4fixed in 6.5.16.0≥ unspecified, ≤ 6.5.15.02023-03-22
CVE-2023-22252 [MEDIUM] CWE-79 CVE-2023-22252: Experience Manager versions 6.5.15.0 (and earlier) are affected by a reflected Cross-Site Scripting Experience Manager versions 6.5.15.0 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-22269P4MEDIUMCVSS 5.4fixed in 6.5.16.0≥ unspecified, ≤ 6.5.15.02023-03-22
CVE-2023-22269 [MEDIUM] CWE-79 CVE-2023-22269: Experience Manager versions 6.5.15.0 (and earlier) are affected by a reflected Cross-Site Scripting Experience Manager versions 6.5.15.0 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-22254P4MEDIUMCVSS 5.4fixed in 6.5.16.0≥ unspecified, ≤ 6.5.15.02023-03-22
CVE-2023-22254 [MEDIUM] CWE-79 CVE-2023-22254: Experience Manager versions 6.5.15.0 (and earlier) are affected by a reflected Cross-Site Scripting Experience Manager versions 6.5.15.0 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2025-64872P4MEDIUMCVSS 4.8fixed in 6.5.24.0fixed in 2025.12.0+1 more2025-12-10
CVE-2025-64872 [MEDIUM] CWE-79 CVE-2025-64872: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-34694P4MEDIUMCVSS 4.8≤ 6.5.24.0v6.5+1 more2026-06-09
CVE-2026-34694 [MEDIUM] CWE-79 CVE-2026-34694: Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored C Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the v
nvd
Adobe Experience Manager vulnerabilities | cvebase