VYPR

Experience Manager

by Adobe Inc.

CVEs (1,275)

  • CVE-2022-38439MedSep 23, 2022
    risk 0.35cvss 5.4epss 0.01

    Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context…

  • CVE-2022-38438MedSep 23, 2022
    risk 0.35cvss 5.4epss 0.01

    Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context…

  • CVE-2022-35664MedSep 16, 2022
    risk 0.35cvss 5.4epss 0.01

    Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context…

  • CVE-2022-34218MedSep 16, 2022
    risk 0.35cvss 5.4epss 0.01

    Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context…

  • CVE-2022-30686MedSep 16, 2022
    risk 0.35cvss 5.4epss 0.01

    Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context…

  • CVE-2022-30685MedSep 16, 2022
    risk 0.35cvss 5.4epss 0.01

    Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context…

  • CVE-2022-30684MedSep 16, 2022
    risk 0.35cvss 5.4epss 0.01

    Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context…

  • CVE-2022-30682MedSep 16, 2022
    risk 0.35cvss 5.4epss 0.01

    Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context…

  • CVE-2022-30681MedSep 16, 2022
    risk 0.35cvss 5.4epss 0.01

    Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context…

  • CVE-2022-30680MedSep 16, 2022
    risk 0.35cvss 5.4epss 0.01

    Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context…

  • CVE-2022-30678MedSep 16, 2022
    risk 0.35cvss 5.4epss 0.01

    Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context…

  • CVE-2022-30677MedSep 16, 2022
    risk 0.35cvss 5.4epss 0.01

    Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context…

  • CVE-2022-35697MedAug 10, 2022
    risk 0.35cvss 5.4epss 0.01

    Adobe Experience Manager Core Components version 2.20.6 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed…

  • CVE-2021-44178MedJan 13, 2022
    risk 0.35cvss 5.4epss 0.01

    AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a reflected Cross-Site Scripting (XSS) vulnerability via the itemResourceType parameter. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious…

  • CVE-2021-40711MedSep 27, 2021
    risk 0.35cvss 5.4epss 0.01

    Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a stored XSS vulnerability when creating Content Fragments. An authenticated attacker can send a malformed POST request to achieve arbitrary code execution. Malicious JavaScript may be executed in a victim’s…

  • CVE-2021-28627MedAug 24, 2021
    risk 0.35cvss 5.4epss 0.01

    Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by a Server-side Request Forgery. An authenticated attacker could leverage this vulnerability to contact systems blocked by the dispatcher. Exploitation of this issue does not…

  • CVE-2020-9743MedSep 10, 2020
    risk 0.35cvss 5.3epss 0.02

    AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by an HTML injection vulnerability in the content editor component that allows unauthenticated users to craft an HTTP request that includes arbitrary HTML code…

  • CVE-2020-9644MedJun 12, 2020
    risk 0.35cvss 5.4epss 0.02

    Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting (stored) vulnerability. Successful exploitation could lead to arbitrary javascript execution in the browser.

  • CVE-2018-12807MedAug 29, 2018
    risk 0.35cvss 5.3epss 0.05

    Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have an input validation bypass vulnerability. Successful exploitation could lead to unauthorized information modification.

  • CVE-2016-4253MedAug 9, 2016
    risk 0.35cvss 5.3epss 0.03

    The Backup functionality in Adobe Experience Manager 5.6.1, 6.0, 6.1, and 6.2 allows attackers to obtain sensitive information via unspecified vectors.