cbcvebase.

Adobe Experience Manager vulnerabilities

1,269 known vulnerabilities affecting adobe/experience_manager.

Total CVEs
1,269
CISA KEV
0
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL15HIGH30MEDIUM1213LOW11

Vulnerabilities

Page 8 of 64
CVE-2026-75643P4MEDIUMCVSS 5.4fixed in 6.5fixed in 6.5.25.0+4 more2026-09-08
CVE-2026-75643 [MEDIUM] CWE-79 CVE-2026-75643: Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
nvd
CVE-2026-75742P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.8.0+3 more2026-09-08
CVE-2026-75742 [MEDIUM] CWE-79 CVE-2026-75742: Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
nvd
CVE-2026-75730P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.8.0+3 more2026-09-08
CVE-2026-75730 [MEDIUM] CWE-79 CVE-2026-75730: Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
nvd
CVE-2026-75733P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.8.0+3 more2026-09-08
CVE-2026-75733 [MEDIUM] CWE-79 CVE-2026-75733: Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
nvd
CVE-2026-75737P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.8.0+3 more2026-09-08
CVE-2026-75737 [MEDIUM] CWE-79 CVE-2026-75737: Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
nvd
CVE-2026-75727P4MEDIUMCVSS 5.4fixed in 6.5.25.0fixed in 2026.8.0+3 more2026-09-08
CVE-2026-75727 [MEDIUM] CWE-79 CVE-2026-75727: Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
nvd
CVE-2026-48355P4MEDIUMCVSS 5.4≤ 6.5.25.0≤ 2020.5.0+3 more2026-07-14
CVE-2026-48355 [MEDIUM] CWE-79 CVE-2026-48355: Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
nvd
CVE-2026-48263P4MEDIUMCVSS 5.4≤ 6.5.25.0≤ 2020.5.0+3 more2026-07-14
CVE-2026-48263 [MEDIUM] CWE-79 CVE-2026-48263: Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
nvd
CVE-2026-27231P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27231 [MEDIUM] CWE-79 CVE-2026-27231: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27226P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27226 [MEDIUM] CWE-79 CVE-2026-27226: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27239P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27239 [MEDIUM] CWE-79 CVE-2026-27239: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27234P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27234 [MEDIUM] CWE-79 CVE-2026-27234: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27229P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27229 [MEDIUM] CWE-79 CVE-2026-27229: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27262P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27262 [MEDIUM] CWE-79 CVE-2026-27262: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27224P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27224 [MEDIUM] CWE-79 CVE-2026-27224: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2026-27223P4MEDIUMCVSS 5.4fixed in 6.5.24.0fixed in 2026.2.0+2 more2026-03-11
CVE-2026-27223 [MEDIUM] CWE-79 CVE-2026-27223: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting ( Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd
CVE-2025-64854P4MEDIUMCVSS 5.4fixed in 6.5fixed in 6.5.25.0+4 more2026-09-08
CVE-2025-64854 [MEDIUM] CWE-79 CVE-2025-64854: Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
nvd
CVE-2025-64584P4MEDIUMCVSS 5.4fixed in 6.5fixed in 6.5.25.0+4 more2026-09-08
CVE-2025-64584 [MEDIUM] CWE-79 CVE-2025-64584: Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
nvd
CVE-2025-64589P4MEDIUMCVSS 5.4fixed in 6.5fixed in 6.5.25.0+4 more2026-09-08
CVE-2025-64589 [MEDIUM] CWE-79 CVE-2025-64589: Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
nvd
CVE-2025-64866P4MEDIUMCVSS 5.4fixed in 6.5fixed in 6.5.25.0+4 more2026-09-08
CVE-2025-64866 [MEDIUM] CWE-79 CVE-2025-64866: Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
nvd
Adobe Experience Manager vulnerabilities | cvebase