VYPR

Experience Manager

by Adobe Inc.

CVEs (1,168)

  • CVE-2025-54253CriKEVAug 5, 2025
    risk 0.84cvss 10.0epss 0.88

    Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not…

  • CVE-2025-49533CriJul 8, 2025
    risk 0.67cvss 9.8epss 0.47

    Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction. Scope is unchanged.

  • CVE-2019-7964CriAug 16, 2019
    risk 0.65cvss 9.8epss 0.10

    Adobe Experience Manager versions 6.5, and 6.4 have an authentication bypass vulnerability. Successful exploitation could lead to remote code execution.

  • CVE-2021-40722CriJan 13, 2022
    risk 0.64cvss 9.8epss 0.03

    AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) injection vulnerability that could be abused by an attacker to achieve RCE.

  • CVE-2019-8088CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.06

    Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2017-3108CriAug 11, 2017
    risk 0.64cvss 9.8epss 0.09

    Adobe Experience Manager 6.2 and earlier has a malicious file execution vulnerability.

  • CVE-2025-54254HigAug 5, 2025
    risk 0.63cvss 8.6epss 0.77

    Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the local…

  • CVE-2025-64537CriDec 10, 2025
    risk 0.61cvss 9.3epss 0.01

    Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by injecting malicious scripts into a web page that are executed in…

  • CVE-2026-34691CriJun 9, 2026
    risk 0.60cvss 9.3epss 0.00

    Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a…

  • CVE-2025-64539CriDec 10, 2025
    risk 0.60cvss 9.3epss 0.00

    Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by injecting malicious scripts into a web page that are executed in…

  • CVE-2025-64538CriDec 10, 2025
    risk 0.60cvss 9.3epss 0.01

    Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by injecting malicious scripts into a web page that are executed in…

  • CVE-2020-24445CriDec 10, 2020
    risk 0.59cvss 9.0epss 0.03

    AEM's Cloud Service offering, as well as version 6.5.6.0 (and below), are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a…

  • CVE-2020-9742CriSep 10, 2020
    risk 0.59cvss 9.0epss 0.02

    AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below) and 6.3.3.8 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Inbox calendar feature. These scripts may be executed in a…

  • CVE-2020-9741CriSep 10, 2020
    risk 0.59cvss 9.0epss 0.02

    The AEM forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) is affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Forms component. These scripts may be executed in a…

  • CVE-2020-9740CriSep 10, 2020
    risk 0.59cvss 9.0epss 0.02

    AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Design Importer. These scripts…

  • CVE-2020-9734CriSep 10, 2020
    risk 0.59cvss 9.0epss 0.02

    The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.1 (and below) is affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Forms component. These scripts may be executed in a…

  • CVE-2020-9732CriSep 10, 2020
    risk 0.59cvss 9.0epss 0.03

    The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Sites component. These scripts may be executed in a…

  • CVE-2025-46840HigJun 10, 2025
    risk 0.57cvss 8.7epss 0.00

    Adobe Experience Manager versions 6.5.22 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. A low privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access.…

  • CVE-2025-46837HigJun 10, 2025
    risk 0.57cvss 8.7epss 0.00

    Adobe Experience Manager versions 6.5.22 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a…

  • CVE-2016-7885HigDec 15, 2016
    risk 0.57cvss 8.8epss 0.03

    Adobe Experience Manager versions 6.2 and earlier have a vulnerability that could be used in Cross-Site Request Forgery attacks.

Page 1 of 59