VYPR

Experience Manager

by Adobe Inc.

CVEs (1,275)

  • CVE-2025-54253CriKEVAug 5, 2025
    risk 0.84cvss 10.0epss 0.88

    Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not…

  • CVE-2025-49533CriJul 8, 2025
    risk 0.67cvss 9.8epss 0.56

    Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction. Scope is unchanged.

  • CVE-2019-7964CriAug 16, 2019
    risk 0.65cvss 9.8epss 0.10

    Adobe Experience Manager versions 6.5, and 6.4 have an authentication bypass vulnerability. Successful exploitation could lead to remote code execution.

  • CVE-2026-19232CriSep 8, 2026
    risk 0.64cvss 9.9epss 0.01

    Adobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. A low-privileged attacker could…

  • CVE-2021-40722CriJan 13, 2022
    risk 0.64cvss 9.8epss 0.03

    AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) injection vulnerability that could be abused by an attacker to achieve RCE.

  • CVE-2019-8088CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.06

    Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2017-3108CriAug 11, 2017
    risk 0.64cvss 9.8epss 0.09

    Adobe Experience Manager 6.2 and earlier has a malicious file execution vulnerability.

  • CVE-2025-54254HigAug 5, 2025
    risk 0.63cvss 8.6epss 0.77

    Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the local…

  • CVE-2026-48359CriJul 14, 2026
    risk 0.62cvss 9.6epss 0.01

    Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to read sensitive…

  • CVE-2026-48259CriJul 14, 2026
    risk 0.62cvss 9.6epss 0.01

    Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could leverage this vulnerability to issue unauthorized server-side requests,…

  • CVE-2025-64538CriDec 10, 2025
    risk 0.61cvss 9.3epss 0.01

    Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by injecting malicious scripts into a web page that are executed in…

  • CVE-2025-64537CriDec 10, 2025
    risk 0.61cvss 9.3epss 0.01

    Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by injecting malicious scripts into a web page that are executed in…

  • CVE-2026-34691CriJun 9, 2026
    risk 0.60cvss 9.3epss 0.01

    Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a…

  • CVE-2025-64539CriDec 10, 2025
    risk 0.60cvss 9.3epss 0.00

    Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by injecting malicious scripts into a web page that are executed in…

  • CVE-2020-24445CriDec 10, 2020
    risk 0.59cvss 9.0epss 0.03

    AEM's Cloud Service offering, as well as version 6.5.6.0 (and below), are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a…

  • CVE-2020-9742CriSep 10, 2020
    risk 0.59cvss 9.0epss 0.02

    AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below) and 6.3.3.8 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Inbox calendar feature. These scripts may be executed in a…

  • CVE-2020-9741CriSep 10, 2020
    risk 0.59cvss 9.0epss 0.02

    The AEM forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) is affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Forms component. These scripts may be executed in a…

  • CVE-2020-9740CriSep 10, 2020
    risk 0.59cvss 9.0epss 0.02

    AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Design Importer. These scripts…

  • CVE-2020-9734CriSep 10, 2020
    risk 0.59cvss 9.0epss 0.02

    The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.1 (and below) is affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Forms component. These scripts may be executed in a…

  • CVE-2020-9732CriSep 10, 2020
    risk 0.59cvss 9.0epss 0.03

    The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Sites component. These scripts may be executed in a…

Page 1 of 64