VYPR

Experience Manager

by Adobe Inc.

CVEs (1,275)

  • CVE-2025-54247MedSep 9, 2025
    risk 0.42cvss 6.5epss 0.00

    Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read…

  • CVE-2025-54246MedSep 9, 2025
    risk 0.42cvss 6.5epss 0.00

    Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write…

  • CVE-2024-43729MedDec 10, 2024
    risk 0.42cvss 6.5epss 0.01

    Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a high impact on…

  • CVE-2021-43762MedJan 13, 2022
    risk 0.42cvss 6.5epss 0.02

    AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a dispatcher bypass vulnerability that could be abused to evade security controls. Sensitive areas of the web application may be exposed through exploitation of the vulnerability.

  • CVE-2021-40712MedSep 27, 2021
    risk 0.42cvss 6.5epss 0.02

    Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a improper input validation vulnerability via the path parameter. An authenticated attacker can send a malformed POST request to achieve server-side denial of service.

  • CVE-2019-8234MedOct 25, 2019
    risk 0.42cvss 6.5epss 0.02

    Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a cross-site request forgery vulnerability. Successful exploitation could lead to sensitive information disclosure.

  • CVE-2019-7953MedJul 18, 2019
    risk 0.42cvss 6.5epss 0.02

    Adobe Experience Manager version 6.4 and ealier have a Cross-Site Request Forgery vulnerability. Successful exploitation could lead to Sensitive Information disclosure in the context of the current user.

  • CVE-2021-28628MedAug 24, 2021
    risk 0.41cvss 6.3epss 0.01

    Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by a Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in…

  • CVE-2021-28625MedAug 24, 2021
    risk 0.41cvss 6.3epss 0.01

    Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by a Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in…

  • CVE-2026-47991MedJun 9, 2026
    risk 0.40cvss 6.1epss 0.00

    Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could construct a malicious URL that redirects a victim to an attacker-controlled…

  • CVE-2025-47094MedJun 10, 2025
    risk 0.40cvss 6.1epss 0.00

    Adobe Experience Manager versions 6.5.22 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of…

  • CVE-2025-47049MedJun 10, 2025
    risk 0.40cvss 6.1epss 0.00

    Adobe Experience Manager versions 6.5.22 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser.…

  • CVE-2022-28820MedApr 21, 2022
    risk 0.40cvss 6.1epss 0.01

    ACS Commons version 5.1.x (and earlier) suffers from a Reflected Cross-site Scripting (XSS) vulnerability in /apps/acs-commons/content/page-compare.html endpoint via the a and b GET parameters. User input submitted via these parameters is not validated or sanitised. An attacker…

  • CVE-2021-40714MedSep 27, 2021
    risk 0.40cvss 6.1epss 0.01

    Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability via the accesskey parameter. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be…

  • CVE-2020-9651MedJun 12, 2020
    risk 0.40cvss 6.1epss 0.02

    Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting (reflected) vulnerability. Successful exploitation could lead to arbitrary javascript execution in the browser.

  • CVE-2020-9648MedJun 12, 2020
    risk 0.40cvss 6.1epss 0.02

    Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting vulnerability. Successful exploitation could lead to arbitrary javascript execution in the browser.

  • CVE-2020-9647MedJun 12, 2020
    risk 0.40cvss 6.1epss 0.02

    Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting (dom-based) vulnerability. Successful exploitation could lead to arbitrary javascript execution in the browser.

  • CVE-2019-16467MedJan 15, 2020
    risk 0.40cvss 6.1epss 0.01

    Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

  • CVE-2019-16466MedJan 15, 2020
    risk 0.40cvss 6.1epss 0.01

    Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

  • CVE-2019-8085MedOct 25, 2019
    risk 0.40cvss 6.1epss 0.01

    Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a reflected cross site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

Page 4 of 64