Adobe Experience Manager vulnerabilities
1,269 known vulnerabilities affecting adobe/experience_manager.
Total CVEs
1,269
CISA KEV
0
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL15HIGH30MEDIUM1213LOW11
Vulnerabilities
Page 6 of 64
CVE-2026-27244P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27244 [MEDIUM] CWE-79 CVE-2026-27244: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27254P4MEDIUMCVSS 5.4fixed in 6.5.24fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27254 [MEDIUM] CWE-79 CVE-2026-27254: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27247P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27247 [MEDIUM] CWE-79 CVE-2026-27247: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27265P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27265 [MEDIUM] CWE-79 CVE-2026-27265: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27252P4MEDIUMCVSS 5.4fixed in 6.5.24fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27252 [MEDIUM] CWE-79 CVE-2026-27252: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27266P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27266 [MEDIUM] CWE-79 CVE-2026-27266: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27249P4MEDIUMCVSS 5.4fixed in 6.5.24fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27249 [MEDIUM] CWE-79 CVE-2026-27249: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27225P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27225 [MEDIUM] CWE-79 CVE-2026-27225: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27255P4MEDIUMCVSS 5.4fixed in 6.5.24fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27255 [MEDIUM] CWE-79 CVE-2026-27255: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27250P4MEDIUMCVSS 5.4fixed in 6.5.24fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27250 [MEDIUM] CWE-79 CVE-2026-27250: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27241P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27241 [MEDIUM] CWE-79 CVE-2026-27241: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27253P4MEDIUMCVSS 5.4fixed in 6.5.24fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27253 [MEDIUM] CWE-79 CVE-2026-27253: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27235P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27235 [MEDIUM] CWE-79 CVE-2026-27235: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27240P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27240 [MEDIUM] CWE-79 CVE-2026-27240: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27230P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27230 [MEDIUM] CWE-79 CVE-2026-27230: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27248P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27248 [MEDIUM] CWE-79 CVE-2026-27248: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27237P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27237 [MEDIUM] CWE-79 CVE-2026-27237: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27232P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27232 [MEDIUM] CWE-79 CVE-2026-27232: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27251P4MEDIUMCVSS 5.4fixed in 6.5.24fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27251 [MEDIUM] CWE-79 CVE-2026-27251: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27257P4MEDIUMCVSS 5.4fixed in 6.5.24fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27257 [MEDIUM] CWE-79 CVE-2026-27257: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd