cbcvebase.

Adobe Experience Manager vulnerabilities

1,165 known vulnerabilities affecting adobe/experience_manager.

Total CVEs
1,165
CISA KEV
0
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL13HIGH29MEDIUM1113LOW10

Vulnerabilities

Page 8 of 59
CVE-2025-64592P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2025.12.0+1 more2025-12-10
CVE-2025-64592 [MEDIUM] CWE-79 CVE-2025-64592: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-64801P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2025.12.0+1 more2025-12-10
CVE-2025-64801 [MEDIUM] CWE-79 CVE-2025-64801: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-64591P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2025.12.0+1 more2025-12-10
CVE-2025-64591 [MEDIUM] CWE-79 CVE-2025-64591: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-47990P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47990 [MEDIUM] CWE-79 CVE-2026-47990: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-48304P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-48304 [MEDIUM] CWE-79 CVE-2026-48304: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47936P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47936 [MEDIUM] CWE-79 CVE-2026-47936: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47974P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47974 [MEDIUM] CWE-79 CVE-2026-47974: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47978P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47978 [MEDIUM] CWE-79 CVE-2026-47978: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-48301P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-48301 [MEDIUM] CWE-79 CVE-2026-48301: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47966P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47966 [MEDIUM] CWE-79 CVE-2026-47966: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47951P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47951 [MEDIUM] CWE-79 CVE-2026-47951: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47975P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47975 [MEDIUM] CWE-79 CVE-2026-47975: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47962P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47962 [MEDIUM] CWE-79 CVE-2026-47962: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47957P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47957 [MEDIUM] CWE-79 CVE-2026-47957: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47954P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47954 [MEDIUM] CWE-79 CVE-2026-47954: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47980P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47980 [MEDIUM] CWE-79 CVE-2026-47980: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47949P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47949 [MEDIUM] CWE-79 CVE-2026-47949: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47973P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47973 [MEDIUM] CWE-79 CVE-2026-47973: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47977P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47977 [MEDIUM] CWE-79 CVE-2026-47977: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
CVE-2026-47981P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.5.0+2 more2026-06-09
CVE-2026-47981 [MEDIUM] CWE-79 CVE-2026-47981: Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cros Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulne
nvd
Adobe Experience Manager vulnerabilities | cvebase