Adobe Experience Manager vulnerabilities
1,165 known vulnerabilities affecting adobe/experience_manager.
Total CVEs
1,165
CISA KEV
0
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL14HIGH30MEDIUM1111LOW10
Vulnerabilities
Page 58 of 59
CVE-2024-43716P4MEDIUMCVSS 4.3fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-43716 [MEDIUM] CWE-284 CVE-2024-43716: Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Access Control vuln
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on confidentiality. Exploitation of this issue does not require user interaction.
nvd
CVE-2024-43717P4MEDIUMCVSS 4.3fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-43717 [MEDIUM] CWE-284 CVE-2024-43717: Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Access Control vuln
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on confidentiality. Exploitation of this issue does not require user interaction.
nvd
CVE-2020-9736P4MEDIUMCVSS 4.8≥ 6.3.0.0, ≤ 6.3.3.8≥ 6.4.0.0, ≤ 6.4.8.1+3 more2020-09-10
CVE-2020-9736 [MEDIUM] CWE-79 CVE-2020-9736: AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and be
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with access to the Content Repository Development Environment to store malicious scripts in certain node fields. These scripts may be executed in a victim’s browser when browsing to the pa
nvd
CVE-2020-9735P4MEDIUMCVSS 4.8≥ 6.3.0.0, ≤ 6.3.3.8≥ 6.4.0.0, ≤ 6.4.8.1+3 more2020-09-10
CVE-2020-9735 [MEDIUM] CWE-79 CVE-2020-9735: AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and be
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with access to the Content Repository Development Environment to store malicious scripts in certain node fields. These scripts may be executed in a victim’s browser when search queries ret
nvd
CVE-2020-9738P4MEDIUMCVSS 4.8≥ 6.3.0.0, ≤ 6.3.3.8≥ 6.4.0.0, ≤ 6.4.8.1+3 more2020-09-10
CVE-2020-9738 [MEDIUM] CWE-79 CVE-2020-9738: AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and be
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with access to the Content Repository Development Environment to store malicious scripts in certain node fields. These scripts may be executed in a victim’s browser when visiting the page
nvd
CVE-2020-9737P4MEDIUMCVSS 4.8≥ 6.3.0.0, ≤ 6.3.3.8≥ 6.4.0.0, ≤ 6.4.8.1+3 more2020-09-10
CVE-2020-9737 [MEDIUM] CWE-79 CVE-2020-9737: AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and be
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with access to the Content Repository Development Environment to store malicious scripts in certain node fields. These scripts may be executed in a victim’s browser when they open the page
nvd
CVE-2024-26049P4MEDIUMCVSS 4.8fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-26049 [MEDIUM] CWE-79 CVE-2024-26049: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-43732P4MEDIUMCVSS 4.6fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-43732 [MEDIUM] CWE-79 CVE-2024-43732: Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scriptin
Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could allow an attacker to execute arbitrary code in the context of the victim's browser. This issue occurs when data from a malicious source is processed by a web application's client-side scripts to update the DOM. Exploita
nvd
CVE-2025-46884P4MEDIUMCVSS 4.8fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46884 [MEDIUM] CWE-79 CVE-2025-46884: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46911P4MEDIUMCVSS 4.8fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46911 [MEDIUM] CWE-79 CVE-2025-46911: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-41842P4MEDIUMCVSS 4.8fixed in 6.5.21fixed in 2024.52024-08-23
CVE-2024-41842 [MEDIUM] CWE-79 CVE-2024-41842: Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-46913P4MEDIUMCVSS 4.8fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46913 [MEDIUM] CWE-79 CVE-2025-46913: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2022-42351P4MEDIUMCVSS 4.3fixed in 6.5.15.0≥ unspecified, ≤ 6.5.14.02022-12-16
CVE-2022-42351 [MEDIUM] CWE-863 CVE-2022-42351: Adobe Experience Manager version 6.5.14 (and earlier) is affected by an Incorrect Authorization vuln
Adobe Experience Manager version 6.5.14 (and earlier) is affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to disclose low level confidentiality information. Exploitation of this issue does not require user interaction.
nvd
CVE-2024-26050P4MEDIUMCVSS 4.8fixed in 6.5.20.0fixed in 2024.3.02024-03-18
CVE-2024-26050 [MEDIUM] CWE-79 CVE-2024-26050: Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2024-41849P4MEDIUMCVSS 4.1fixed in 6.5.21fixed in 2024.52024-08-23
CVE-2024-41849 [MEDIUM] CWE-20 CVE-2024-41849: Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vu
Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could lead to a security feature bypass. An low-privileged attacker could leverage this vulnerability to slightly affect the integrity of the page. Exploitation of this issue requires user interaction and scope is changed.
nvd
CVE-2026-48288P4LOWCVSS 3.5fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-48288 [LOW] CWE-20 CVE-2026-48288: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper I
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction
nvd
CVE-2026-48289P4LOWCVSS 3.5fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-48289 [LOW] CWE-20 CVE-2026-48289: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper I
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction
nvd
CVE-2024-52831P4LOWCVSS 3.5fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-52831 [LOW] CWE-20 CVE-2024-52831: Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation vu
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and affect the integrity of the page. Exploitation of this issue requires user interaction.
nvd
CVE-2024-43755P4LOWCVSS 3.5fixed in 6.5.22.0fixed in 2024.11.02024-12-10
CVE-2024-43755 [LOW] CWE-20 CVE-2024-43755: Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation vu
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and affect the integrity of the page. Exploitation of this issue requires user interaction.
nvd
CVE-2025-47096P4LOWCVSS 3.5fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-47096 [LOW] CWE-20 CVE-2025-47096: Adobe Experience Manager versions 6.5.22 and earlier are affected by an Improper Input Validation vu
Adobe Experience Manager versions 6.5.22 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass, allowing a low impact to the integrity of the component. Exploitation of this issue requires user interaction in that a victim must interact with the malicious content. Low privileges are require
nvd