VYPR

Connect

by Adobe Inc.

CVEs (86)

  • CVE-2021-40721MedOct 15, 2021
    risk 0.40cvss 6.1epss 0.01

    Adobe Connect version 11.2.3 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the…

  • CVE-2021-21080MedMar 12, 2021
    risk 0.40cvss 6.1epss 0.01

    Adobe Connect version 11.0.7 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious JavaScript content that may be executed within the context of the victim's browser when they browse to…

  • CVE-2021-21079MedMar 12, 2021
    risk 0.40cvss 6.1epss 0.01

    Adobe Connect version 11.0.7 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious JavaScript content that may be executed within the context of the victim's browser when they browse to…

  • CVE-2020-24443MedNov 12, 2020
    risk 0.40cvss 6.1epss 0.01

    Adobe Connect version 11.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's…

  • CVE-2020-24442MedNov 12, 2020
    risk 0.40cvss 6.1epss 0.01

    Adobe Connect version 11.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's…

  • CVE-2018-4921MedMay 19, 2018
    risk 0.40cvss 6.1epss 0.05

    Adobe Connect versions 9.7 and earlier have an exploitable unrestricted SWF file upload vulnerability. Successful exploitation could lead to information disclosure.

  • CVE-2017-11290MedDec 9, 2017
    risk 0.40cvss 6.1epss 0.04

    An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A UI Redress (or Clickjacking) vulnerability exists. This issue has been resolved by adding a feature that enables Connect administrators to protect users from UI redressing (or clickjacking) attacks.

  • CVE-2017-11289MedDec 9, 2017
    risk 0.40cvss 6.1epss 0.04

    An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A reflected cross-site scripting vulnerability exists that can result in information disclosure.

  • CVE-2017-11288MedDec 9, 2017
    risk 0.40cvss 6.1epss 0.04

    An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A reflected cross-site scripting vulnerability exists that can result in information disclosure.

  • CVE-2017-11287MedDec 9, 2017
    risk 0.40cvss 6.1epss 0.04

    An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A reflected cross-site scripting vulnerability exists that can result in information disclosure.

  • CVE-2017-3103MedJul 17, 2017
    risk 0.40cvss 6.1epss 0.04

    Adobe Connect versions 9.6.1 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to a stored cross-site scripting attack.

  • CVE-2017-3102MedJul 17, 2017
    risk 0.40cvss 6.1epss 0.04

    Adobe Connect versions 9.6.1 and earlier have a reflected cross-site scripting vulnerability. Successful exploitation could lead to a reflected cross-site scripting attack.

  • CVE-2025-30316MedMay 13, 2025
    risk 0.35cvss 5.4epss 0.00

    Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when…

  • CVE-2024-54041MedDec 10, 2024
    risk 0.35cvss 5.4epss 0.00

    Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they…

  • CVE-2024-54040MedDec 10, 2024
    risk 0.35cvss 5.4epss 0.00

    Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they…

  • CVE-2024-54039MedDec 10, 2024
    risk 0.35cvss 5.4epss 0.00

    Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they…

  • CVE-2021-36063MedSep 1, 2021
    risk 0.35cvss 5.4epss 0.01

    Adobe Connect version 11.2.2 (and earlier) is affected by a Reflected Cross-site Scripting vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to…

  • CVE-2021-36062MedSep 1, 2021
    risk 0.35cvss 5.4epss 0.01

    Adobe Connect version 11.2.2 (and earlier) is affected by a Reflected Cross-site Scripting vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. If an attacker is able to convince a victim to visit a URL referencing a…

  • CVE-2021-36061MedSep 1, 2021
    risk 0.35cvss 5.4epss 0.02

    Adobe Connect version 11.2.2 (and earlier) is affected by a secure design principles violation vulnerability via the 'pbMode' parameter. An unauthenticated attacker could leverage this vulnerability to edit or delete recordings on the Connect environment. Exploitation of this…

  • CVE-2018-19718MedJan 18, 2019
    risk 0.35cvss 5.3epss 0.04

    Adobe Connect versions 9.8.1 and earlier have a session token exposure vulnerability. Successful exploitation could lead to exposure of the privileges granted to a session.

Page 4 of 5