Adobe Experience Manager Forms vulnerabilities

8 known vulnerabilities affecting adobe/experience_manager_forms.

Total CVEs
8
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH3MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2025-54253CRITICALCVSS 10.0KEV≤ 6.5.23.02025-08-05
CVE-2025-54253 [CRITICAL] CWE-863 CVE-2025-54253: Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerabilit Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.
nvd
CVE-2025-54254HIGHCVSS 8.6≤ 6.5.23.02025-08-05
CVE-2025-54254 [HIGH] CWE-611 CVE-2025-54254: Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the local file system, scope is changed. Exploitation of this issue does not require
nvd
CVE-2020-9732CRITICALCVSS 9.0v6.4.8.1v6.5.5.02020-09-10
CVE-2020-9732 [CRITICAL] CWE-79 CVE-2020-9732: The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) are affected by a stor The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Sites component. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.
nvd
CVE-2020-9733HIGHCVSS 7.5v6.4.8.1v6.5.5.02020-09-10
CVE-2020-9733 [HIGH] CWE-200 CVE-2020-9733: An AEM java servlet in AEM versions 6.5.5.0 (and below) and 6.4.8.1 (and below) executes with the pe An AEM java servlet in AEM versions 6.5.5.0 (and below) and 6.4.8.1 (and below) executes with the permissions of a high privileged service user. If exploited, this could lead to read-only access to sensitive data in an AEM repository.
nvd
CVE-2019-8089MEDIUMCVSS 6.1v6.3v6.4+1 more2019-10-22
CVE-2019-8089 [MEDIUM] CWE-79 CVE-2019-8089: Adobe Experience Manager Forms versions 6.3-6.5 have a reflected cross-site scripting vulnerability. Adobe Experience Manager Forms versions 6.3-6.5 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
nvd
CVE-2019-7129MEDIUMCVSS 6.1v6.2v6.3+1 more2019-05-29
CVE-2019-7129 [MEDIUM] CWE-79 CVE-2019-7129: Adobe Experience Manager Forms versions 6.2, 6.3 and 6.4 have a stored cross-site scripting vulnerab Adobe Experience Manager Forms versions 6.2, 6.3 and 6.4 have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
nvd
CVE-2017-3067HIGHCVSS 7.5v6.0v6.1+1 more2017-05-09
CVE-2017-3067 [HIGH] CWE-200 CVE-2017-3067: Adobe Experience Manager Forms versions 6.2, 6.1, 6.0 have an information disclosure vulnerability r Adobe Experience Manager Forms versions 6.2, 6.1, 6.0 have an information disclosure vulnerability resulting from abuse of the pre-population service in AEM Forms.
nvd
CVE-2016-6934MEDIUMCVSS 6.1≤ 6.22016-12-15
CVE-2016-6934 [MEDIUM] CWE-79 CVE-2016-6934: Adobe Experience Manager Forms versions 6.2 and earlier, LiveCycle 11.0.1, LiveCycle 10.0.4 have an Adobe Experience Manager Forms versions 6.2 and earlier, LiveCycle 11.0.1, LiveCycle 10.0.4 have an input validation issue in the PMAdmin module that could be used in cross-site scripting attacks.
nvd