Adobe Experience Manager vulnerabilities

1,088 known vulnerabilities affecting adobe/experience_manager.

Total CVEs
1,088
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH27MEDIUM1042LOW8

Vulnerabilities

Page 6 of 55
CVE-2025-64607MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2025.12.0+1 more2025-12-10
CVE-2025-64607 [MEDIUM] CWE-79 CVE-2025-64607: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-64569MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2025.12.0+1 more2025-12-10
CVE-2025-64569 [MEDIUM] CWE-79 CVE-2025-64569: Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scriptin Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute malicious scripts in the context of the victim's browser. Exploitation of this issue requires user interaction, such as visiting a crafted URL or interacting with a m
nvd
CVE-2025-64833MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2025.12.0+1 more2025-12-10
CVE-2025-64833 [MEDIUM] CWE-79 CVE-2025-64833: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-64826MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2025.12.0+1 more2025-12-10
CVE-2025-64826 [MEDIUM] CWE-79 CVE-2025-64826: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-64853MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2025.12.0+1 more2025-12-10
CVE-2025-64853 [MEDIUM] CWE-79 CVE-2025-64853: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-64825MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2025.12.0+1 more2025-12-10
CVE-2025-64825 [MEDIUM] CWE-79 CVE-2025-64825: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-64602MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2025.12.0+1 more2025-12-10
CVE-2025-64602 [MEDIUM] CWE-79 CVE-2025-64602: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-64604MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2025.12.0+1 more2025-12-10
CVE-2025-64604 [MEDIUM] CWE-79 CVE-2025-64604: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-64814MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2025.12.0+1 more2025-12-10
CVE-2025-64814 [MEDIUM] CWE-79 CVE-2025-64814: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-64603MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2025.12.0+1 more2025-12-10
CVE-2025-64603 [MEDIUM] CWE-79 CVE-2025-64603: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-64606MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2025.12.0+1 more2025-12-10
CVE-2025-64606 [MEDIUM] CWE-79 CVE-2025-64606: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-64796MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2025.12.0+1 more2025-12-10
CVE-2025-64796 [MEDIUM] CWE-79 CVE-2025-64796: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-64586MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2025.12.0+1 more2025-12-10
CVE-2025-64586 [MEDIUM] CWE-79 CVE-2025-64586: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-64583MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2025.12.0+1 more2025-12-10
CVE-2025-64583 [MEDIUM] CWE-79 CVE-2025-64583: Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scriptin Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute malicious scripts in the context of the victim's browser. Exploitation of this issue requires user interaction, such as visiting a crafted URL or interacting with a m
nvd
CVE-2025-64791MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2025.12.0+1 more2025-12-10
CVE-2025-64791 [MEDIUM] CWE-79 CVE-2025-64791: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-64564MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2025.12.0+1 more2025-12-10
CVE-2025-64564 [MEDIUM] CWE-79 CVE-2025-64564: Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scriptin Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute malicious scripts in the context of the victim's browser. Exploitation of this issue requires user interaction, such as visiting a crafted URL or interacting with a m
nvd
CVE-2025-64566MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2025.12.0+1 more2025-12-10
CVE-2025-64566 [MEDIUM] CWE-79 CVE-2025-64566: Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scriptin Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute malicious scripts in the context of the victim's browser. Exploitation of this issue requires user interaction, such as visiting a crafted URL or interacting with a m
nvd
CVE-2025-64582MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2025.12.0+1 more2025-12-10
CVE-2025-64582 [MEDIUM] CWE-79 CVE-2025-64582: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-64799MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2025.12.0+1 more2025-12-10
CVE-2025-64799 [MEDIUM] CWE-79 CVE-2025-64799: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-64887MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2025.12.0+1 more2025-12-10
CVE-2025-64887 [MEDIUM] CWE-79 CVE-2025-64887: Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scriptin Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute malicious scripts in the context of the victim's browser. Exploitation of this issue requires user interaction, such as visiting a crafted URL or interacting with a m
nvd