VendorsAdobeconnectall versions
Vulnerabilities

Adobe Connect

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

74CVEs
CVE-2017-11291
An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A Server-Side Request Forgery (SSRF) vulnerability exists that could be abused to bypass network access controls.
Published 2017-12-09 · Modified
10.0EPSS 0.055
CVE-2016-0949
Adobe Connect before 9.5.2 allows remote attackers to have an unspecified impact via a crafted parameter in a URL.
Published 2016-02-10 · Modified
10.0EPSS 0.044
CVE-2018-12804
Adobe Connect versions 9.7.5 and earlier have an Authentication Bypass vulnerability. Successful exploitation could lead to session hijacking.
Published 2018-07-20 · Modified
9.8EPSS 0.111
CVE-2018-12805
Adobe Connect versions 9.7.5 and earlier have an Insecure Library Loading vulnerability. Successful exploitation could lead to privilege escalation.
Published 2018-07-20 · Modified
9.8EPSS 0.041
CVE-2021-40719
Adobe Connect Deserialization of Untrusted Data Remote Code Execution
Published 2021-10-21 · Modified
9.8EPSS 0.035
CVE-2023-4662
RCE in Saphira Connect
Published 2023-09-15 · Modified
9.8EPSS 0.012
CVE-2023-4661
SQLi in Saphira Connect
Published 2023-09-15 · Modified
9.8EPSS 0.009
CVE-2026-27303
Adobe Connect | Deserialization of Untrusted Data (CWE-502)
Published 2026-04-14 · Analyzed
9.6EPSS 0.019
CVE-2026-34615
Adobe Connect | Deserialization of Untrusted Data (CWE-502)
Published 2026-04-14 · Analyzed
9.3EPSS 0.018
CVE-2024-54032
Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2024-12-10 · Analyzed
9.3EPSS 0.008
CVE-2026-27243
Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2026-04-14 · Analyzed
9.3EPSS 0.007
CVE-2026-27246
Adobe Connect | Cross-site Scripting (DOM-based XSS) (CWE-79)
Published 2026-04-14 · Analyzed
9.3EPSS 0.007
CVE-2026-27245
Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2026-04-14 · Analyzed
9.3EPSS 0.007
CVE-2024-54036
Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2024-12-10 · Analyzed
9.3EPSS 0.007
CVE-2024-54034
Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2024-12-10 · Analyzed
9.3EPSS 0.007
CVE-2025-49553
Adobe Connect | Cross-site Scripting (DOM-based XSS) (CWE-79)
Published 2025-10-14 · Analyzed
9.3EPSS 0.005
CVE-2025-43567
Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2025-05-13 · Analyzed
9.3EPSS 0.005
CVE-2018-4923
Adobe Connect versions 9.7 and earlier have an exploitable OS Command Injection. Successful exploitation could lead to arbitrary file deletion.
Published 2018-05-19 · Modified
9.1EPSS 0.094
CVE-2016-0948
Cross-site request forgery (CSRF) vulnerability in Adobe Connect before 9.5.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
Published 2016-02-10 · Modified
8.8EPSS 0.019
CVE-2023-4665
Privilage Escalation in Saphira Connect
Published 2023-09-15 · Modified
8.8EPSS 0.010
CVE-2023-4664
Privilage Escalation in Saphira Connect
Published 2023-09-15 · Modified
8.8EPSS 0.009
CVE-2026-34617
Adobe Connect | Cross-site Scripting (XSS) (CWE-79)
Published 2026-04-14 · Analyzed
8.7EPSS 0.007
CVE-2024-54037
Adobe Connect | Cross-site Scripting (DOM-based XSS) (CWE-79)
Published 2024-12-10 · Analyzed
8.1EPSS 0.009
CVE-2025-49552
Adobe Connect | Cross-site Scripting (DOM-based XSS) (CWE-79)
Published 2025-10-14 · Analyzed
8.1EPSS 0.004
CVE-2021-21085
Adobe Connect CSV injection via export feature could lead to code execution
Published 2021-03-12 · Modified
7.8EPSS 0.037
CVE-2016-4118
Untrusted search path vulnerability in the installer in Adobe Connect Add-In before 11.9.976.291 on Windows allows local users to gain privileges via unspecified vectors.
Published 2016-05-30 · Modified
7.8EPSS 0.009
CVE-2018-4994
Adobe Connect versions 9.7.5 and earlier have an exploitable Authentication Bypass vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2018-05-19 · Modified
7.5EPSS 0.095
CVE-2017-3101
Adobe Connect versions 9.6.1 and earlier have a clickjacking vulnerability. Successful exploitation could lead to a clickjacking attack.
Published 2017-07-14 · Modified
7.5EPSS 0.056
CVE-2016-7851
Adobe Connect version 9.5.6 and earlier does not adequately validate input in the events registration module. This vulnerability could be exploited in cross-site scripting attacks.
Published 2016-11-08 · Modified
6.11 PoCEPSS 0.070
CVE-2018-4921
Adobe Connect versions 9.7 and earlier have an exploitable unrestricted SWF file upload vulnerability. Successful exploitation could lead to information disclosure.
Published 2018-05-19 · Modified
6.1EPSS 0.042
CVE-2017-11290
An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A UI Redress (or Clickjacking) vulnerability exists. This issue has been resolved by adding a feature that enables Connect administrators to protect users from UI redressing (or clickjacking) attacks.
Published 2017-12-09 · Modified
6.1EPSS 0.030
CVE-2017-11287
An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A reflected cross-site scripting vulnerability exists that can result in information disclosure.
Published 2017-12-09 · Modified
6.1EPSS 0.029
CVE-2017-11288
An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A reflected cross-site scripting vulnerability exists that can result in information disclosure.
Published 2017-12-09 · Modified
6.1EPSS 0.029
CVE-2017-11289
An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A reflected cross-site scripting vulnerability exists that can result in information disclosure.
Published 2017-12-09 · Modified
6.1EPSS 0.029
CVE-2017-3103
Adobe Connect versions 9.6.1 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to a stored cross-site scripting attack.
Published 2017-07-14 · Modified
6.1EPSS 0.029
CVE-2017-3102
Adobe Connect versions 9.6.1 and earlier have a reflected cross-site scripting vulnerability. Successful exploitation could lead to a reflected cross-site scripting attack.
Published 2017-07-14 · Modified
6.1EPSS 0.029
CVE-2020-24443
Reflected Cross-Site Scripting (XSS) in Adobe Connect
Published 2020-11-12 · Modified
6.1EPSS 0.015
CVE-2020-24442
Reflected Cross-Site Scripting (XSS) in Adobe Connect
Published 2020-11-12 · Modified
6.1EPSS 0.015
CVE-2021-36062
Adobe Connect Reflected Cross-site Scripting via 'campaign-id' parameter
Published 2021-09-01 · Modified
6.1EPSS 0.014
CVE-2021-36063
Adobe Connect Reflected Cross-site Scripting via 'isTabletDeviceHTML' parameter
Published 2021-09-01 · Modified
6.1EPSS 0.014
1 / 2Next →