VYPR

Experience Manager

by Adobe Inc.

CVEs (1,168)

  • CVE-2019-8087HigOct 25, 2019
    risk 0.49cvss 7.5epss 0.04

    Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitive information disclosure.

  • CVE-2019-8082HigOct 25, 2019
    risk 0.49cvss 7.5epss 0.03

    Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitive information disclosure.

  • CVE-2019-8081HigOct 25, 2019
    risk 0.49cvss 7.5epss 0.03

    Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have an authentication bypass vulnerability. Successful exploitation could lead to sensitive information disclosure.

  • CVE-2018-5004HigJul 20, 2018
    risk 0.49cvss 7.5epss 0.04

    Adobe Experience Manager versions 6.2 and 6.3 have a Server-Side Request Forgery vulnerability. Successful exploitation could lead to sensitive information disclosure.

  • CVE-2018-12809HigJul 20, 2018
    risk 0.49cvss 7.5epss 0.05

    Adobe Experience Manager versions 6.4 and earlier have a Server-Side Request Forgery vulnerability. Successful exploitation could lead to sensitive information disclosure.

  • CVE-2017-3111HigDec 9, 2017
    risk 0.49cvss 7.5epss 0.07

    An issue was discovered in Adobe Experience Manager 6.3, 6.2, 6.1, 6.0. Sensitive tokens are included in http GET requests under certain circumstances.

  • CVE-2017-3110HigAug 11, 2017
    risk 0.49cvss 7.5epss 0.05

    Adobe Experience Manager 6.1 and earlier has a sensitive data exposure vulnerability.

  • CVE-2017-3107HigAug 11, 2017
    risk 0.49cvss 7.5epss 0.07

    Adobe Experience Manager 6.3 and earlier has a misconfiguration vulnerability.

  • CVE-2016-0958HigFeb 10, 2016
    risk 0.49cvss 7.5epss 0.04

    Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 might allow remote attackers to have an unspecified impact via a crafted serialized Java object.

  • CVE-2021-21084HigJun 28, 2021
    risk 0.48cvss 7.3epss 0.02

    AEM's Cloud Service offering, as well as versions 6.5.7.0 (and below), 6.4.8.3 (and below) and 6.3.3.8 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields.…

  • CVE-2020-9738MedSep 10, 2020
    risk 0.44cvss 6.8epss 0.02

    AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with access to the Content Repository Development Environment to store malicious scripts in certain node fields.…

  • CVE-2020-9737MedSep 10, 2020
    risk 0.44cvss 6.8epss 0.02

    AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with access to the Content Repository Development Environment to store malicious scripts in certain node fields.…

  • CVE-2020-9736MedSep 10, 2020
    risk 0.44cvss 6.8epss 0.02

    AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with access to the Content Repository Development Environment to store malicious scripts in certain node fields.…

  • CVE-2020-9735MedSep 10, 2020
    risk 0.44cvss 6.8epss 0.02

    AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with access to the Content Repository Development Environment to store malicious scripts in certain node fields.…

  • CVE-2025-54249MedSep 9, 2025
    risk 0.42cvss 6.5epss 0.02

    Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to manipulate server-side requests and bypass…

  • CVE-2025-54247MedSep 9, 2025
    risk 0.42cvss 6.5epss 0.00

    Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read…

  • CVE-2025-54246MedSep 9, 2025
    risk 0.42cvss 6.5epss 0.00

    Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write…

  • CVE-2024-43729MedDec 10, 2024
    risk 0.42cvss 6.5epss 0.01

    Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a high impact on…

  • CVE-2021-43762MedJan 13, 2022
    risk 0.42cvss 6.5epss 0.02

    AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a dispatcher bypass vulnerability that could be abused to evade security controls. Sensitive areas of the web application may be exposed through exploitation of the vulnerability.

  • CVE-2021-40712MedSep 27, 2021
    risk 0.42cvss 6.5epss 0.02

    Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a improper input validation vulnerability via the path parameter. An authenticated attacker can send a malformed POST request to achieve server-side denial of service.

Page 3 of 59