cbcvebase.

Adobe Experience Manager vulnerabilities

1,269 known vulnerabilities affecting adobe/experience_manager.

Total CVEs
1,269
CISA KEV
0
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL15HIGH30MEDIUM1213LOW11

Vulnerabilities

Page 61 of 64
CVE-2022-42345P4MEDIUMCVSS 5.4fixed in 6.5.15.0≥ unspecified, ≤ 6.5.14.02022-12-19
CVE-2022-42345 [MEDIUM] CWE-79 CVE-2022-42345: Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scriptin Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2022-42356P4MEDIUMCVSS 5.4fixed in 6.5.15.0≥ unspecified, ≤ 6.5.14.02022-12-19
CVE-2022-42356 [MEDIUM] CWE-79 CVE-2022-42356: Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scriptin Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2022-35693P4MEDIUMCVSS 5.4fixed in 6.5.15.0≥ unspecified, ≤ 6.5.14.02022-12-19
CVE-2022-35693 [MEDIUM] CWE-79 CVE-2022-35693: Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scriptin Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2022-44488P4MEDIUMCVSS 5.4fixed in 6.5.15.0≥ unspecified, ≤ 6.5.14.02022-12-19
CVE-2022-44488 [MEDIUM] CWE-601 CVE-2022-44488: Adobe Experience Manager version 6.5.14 (and earlier) is affected by a URL Redirection to Untrusted Adobe Experience Manager version 6.5.14 (and earlier) is affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.
nvd
CVE-2024-26105P4MEDIUMCVSS 5.4fixed in 6.5.20.0fixed in 2024.3.02024-03-18
CVE-2024-26105 [MEDIUM] CWE-79 CVE-2024-26105: Adobe Experience Manager versions 6.5.19 and earlier are affected by a reflected Cross-Site Scriptin Adobe Experience Manager versions 6.5.19 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2024-26103P4MEDIUMCVSS 5.4fixed in 6.5.20.0fixed in 2024.3.02024-03-18
CVE-2024-26103 [MEDIUM] CWE-79 CVE-2024-26103: Adobe Experience Manager versions 6.5.19 and earlier are affected by a reflected Cross-Site Scriptin Adobe Experience Manager versions 6.5.19 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2024-26104P4MEDIUMCVSS 5.4fixed in 6.5.20.0fixed in 2024.3.02024-03-18
CVE-2024-26104 [MEDIUM] CWE-79 CVE-2024-26104: Adobe Experience Manager versions 6.5.19 and earlier are affected by a reflected Cross-Site Scriptin Adobe Experience Manager versions 6.5.19 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2024-26118P4MEDIUMCVSS 5.4fixed in 6.5.20.0fixed in 2024.3.02024-03-18
CVE-2024-26118 [MEDIUM] CWE-79 CVE-2024-26118: Adobe Experience Manager versions 6.5.19 and earlier are affected by a reflected Cross-Site Scriptin Adobe Experience Manager versions 6.5.19 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2024-26102P4MEDIUMCVSS 5.4fixed in 6.5.20.0fixed in 2024.3.02024-03-18
CVE-2024-26102 [MEDIUM] CWE-79 CVE-2024-26102: Adobe Experience Manager versions 6.5.19 and earlier are affected by a reflected Cross-Site Scriptin Adobe Experience Manager versions 6.5.19 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2024-26107P4MEDIUMCVSS 5.4fixed in 6.5.20.0fixed in 2024.3.02024-03-18
CVE-2024-26107 [MEDIUM] CWE-79 CVE-2024-26107: Adobe Experience Manager versions 6.5.19 and earlier are affected by a reflected Cross-Site Scriptin Adobe Experience Manager versions 6.5.19 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2024-26106P4MEDIUMCVSS 5.4fixed in 6.5.20.0fixed in 2024.3.02024-03-18
CVE-2024-26106 [MEDIUM] CWE-79 CVE-2024-26106: Adobe Experience Manager versions 6.5.19 and earlier are affected by a reflected Cross-Site Scriptin Adobe Experience Manager versions 6.5.19 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-38215P4MEDIUMCVSS 5.4fixed in 6.5.18.02023-09-13
CVE-2023-38215 [MEDIUM] CWE-79 CVE-2023-38215: Adobe Experience Manager versions 6.5.17 and earlier are affected by a reflected Cross-Site Scriptin Adobe Experience Manager versions 6.5.17 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-38214P4MEDIUMCVSS 5.4≤ 6.5.172023-09-13
CVE-2023-38214 [MEDIUM] CWE-79 CVE-2023-38214: Adobe Experience Manager versions 6.5.17 and earlier are affected by a reflected Cross-Site Scriptin Adobe Experience Manager versions 6.5.17 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2024-26101P4MEDIUMCVSS 5.4fixed in 6.5.20.0fixed in 2024.3.02024-03-18
CVE-2024-26101 [MEDIUM] CWE-79 CVE-2024-26101: Adobe Experience Manager versions 6.5.19 and earlier are affected by a reflected Cross-Site Scriptin Adobe Experience Manager versions 6.5.19 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2024-36206P4MEDIUMCVSS 5.4fixed in 6.5.21fixed in 2024.52024-06-13
CVE-2024-36206 [MEDIUM] CWE-79 CVE-2024-36206: Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scriptin Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-51463P4MEDIUMCVSS 5.4≤ 6.5.182024-01-18
CVE-2023-51463 [MEDIUM] CWE-79 CVE-2023-51463: Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scriptin Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-51459P4MEDIUMCVSS 5.4≤ 6.5.18.0fixed in 2023.11.02023-12-20
CVE-2023-51459 [MEDIUM] CWE-79 CVE-2023-51459: Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scriptin Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2023-51462P4MEDIUMCVSS 5.4≤ 6.5.18fixed in 2023.11.02023-12-20
CVE-2023-51462 [MEDIUM] CWE-79 CVE-2023-51462: Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scriptin Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
nvd
CVE-2026-34694P4MEDIUMCVSS 4.8≤ 6.5.24.0v6.5+1 more2026-06-09
CVE-2026-34694 [MEDIUM] CWE-79 CVE-2026-34694: Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored C Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the v
nvd
CVE-2025-46920P4MEDIUMCVSS 4.6fixed in 6.5.23.0fixed in 2025.5.02025-06-10
CVE-2025-46920 [MEDIUM] CWE-79 CVE-2025-46920: Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
Adobe Experience Manager vulnerabilities | cvebase