VendorsAdobeexperience_managerall versions
Vulnerabilities

Adobe Experience Manager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1265CVEs
CVE-2019-7964
Adobe Experience Manager versions 6.5, and 6.4 have an authentication bypass vulnerability. Successful exploitation could lead to remote code execution.
Published 2019-08-16 · Modified
10.0EPSS 0.102
CVE-2026-19232
Adobe Experience Manager | Incorrect Authorization (CWE-863)
Published 2026-09-08 · Analyzed
9.9EPSS 0.006
CVE-2025-49533
Adobe Experience Manager (MS) | Deserialization of Untrusted Data (CWE-502)
Published 2025-07-08 · Analyzed
9.8EPSS 0.529
CVE-2017-3108
Adobe Experience Manager 6.2 and earlier has a malicious file execution vulnerability.
Published 2017-08-11 · Modified
9.8EPSS 0.086
CVE-2019-8088
Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
Published 2019-10-25 · Modified
9.8EPSS 0.058
CVE-2021-40722
AEM Forms Improper Restriction of XML External Entity Reference
Published 2022-01-13 · Modified
9.8EPSS 0.033
CVE-2024-26029
Adobe Experience Manager | Improper Access Control (CWE-284)
Published 2024-06-13 · Modified
9.8EPSS 0.009
CVE-2026-48359
Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
Published 2026-07-14 · Analyzed
9.6EPSS 0.010
CVE-2026-48259
Adobe Experience Manager | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2026-07-14 · Analyzed
9.6EPSS 0.009
CVE-2025-64537
Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Published 2025-12-10 · Analyzed
9.3EPSS 0.007
CVE-2025-64538
Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Published 2025-12-10 · Analyzed
9.3EPSS 0.006
CVE-2025-64539
Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Published 2025-12-10 · Analyzed
9.3EPSS 0.005
CVE-2026-34691
Adobe Experience Manager Forms JEE | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-06-09 · Analyzed
9.3EPSS 0.004
CVE-2020-9732
Stored XSS in AEM Sites Components
Published 2020-09-10 · Modified
9.0EPSS 0.028
CVE-2020-24445
Cross-site Scripting Vulnerability in Commenting Function of Adobe Experience Manager (AEM)
Published 2020-12-10 · Modified
9.0EPSS 0.026
CVE-2020-9734
Stored XSS in AEM Forms component
Published 2020-09-10 · Modified
9.0EPSS 0.019
CVE-2020-9740
Stored XSS in AEM Design Importer Component
Published 2020-09-10 · Modified
9.0EPSS 0.019
CVE-2020-9741
Stored XSS in AEM Forms Components
Published 2020-09-10 · Modified
9.0EPSS 0.019
CVE-2020-9742
Reflected XSS in AEM Inbox module
Published 2020-09-10 · Modified
9.0EPSS 0.018
CVE-2016-7885
Adobe Experience Manager versions 6.2 and earlier have a vulnerability that could be used in Cross-Site Request Forgery attacks.
Published 2016-12-15 · Modified
8.8EPSS 0.034
CVE-2021-28627
Adobe Experience Manager Server-side Request Forgery could lead to Security feature bypass
Published 2021-08-24 · Modified
8.8EPSS 0.013
CVE-2025-46840
Adobe Experience Manager | Improper Authorization (CWE-285)
Published 2025-06-10 · Analyzed
8.7EPSS 0.004
CVE-2025-46837
Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2025-06-10 · Analyzed
8.7EPSS 0.004
CVE-2026-48310
Adobe Experience Manager | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-07-14 · Analyzed
8.6EPSS 0.010
CVE-2026-48252
Adobe Experience Manager | Missing Authentication for Critical Function (CWE-306)
Published 2026-07-14 · Analyzed
8.6EPSS 0.009
CVE-2021-43765
Adobe Experience Manager Stored XSS in the Carousel Set
Published 2022-01-13 · Modified
8.1EPSS 0.016
CVE-2021-44176
Adobe Experience Manager Stored XSS in workflow Stages parameter
Published 2022-01-13 · Modified
8.1EPSS 0.016
CVE-2021-44177
Adobe Experience Manager Stored XSS in user name parameter in the package manager
Published 2022-01-13 · Modified
8.1EPSS 0.016
CVE-2021-43764
Adobe Experience Manager Stored XSS in the Spin Set
Published 2022-01-13 · Modified
8.0EPSS 0.015
CVE-2021-43761
Adobe Experience Manager Stored XSS on Edit Tag page via Localization input
Published 2022-01-13 · Modified
8.0EPSS 0.011
CVE-2026-34693
Adobe Experience Manager Forms JEE | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2026-06-09 · Analyzed
8.0EPSS 0.003
CVE-2016-0957
Dispatcher before 4.1.5 in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 does not properly implement a URL filter, which allows remote attackers to bypass dispatcher rules via unspecified vectors.
Published 2016-02-10 · Modified
7.8EPSS 0.520
CVE-2016-0956
The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sensitive information via unspecified vectors.
Published 2016-02-10 · Modified
7.81 PoCEPSS 0.512
CVE-2016-0958
Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 might allow remote attackers to have an unspecified impact via a crafted serialized Java object.
Published 2016-02-10 · Modified
7.8EPSS 0.039
CVE-2025-54248
Adobe Experience Manager | Improper Input Validation (CWE-20)
Published 2025-09-09 · Analyzed
7.7EPSS 0.054
CVE-2018-5006
Adobe Experience Manager versions 6.4 and earlier have a Server-Side Request Forgery vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2018-07-20 · Modified
7.5EPSS 0.538
CVE-2019-8086
Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2019-10-25 · Modified
7.5EPSS 0.225
CVE-2019-16469
Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an expression language injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2020-01-15 · Modified
7.5EPSS 0.172
CVE-2017-3107
Adobe Experience Manager 6.3 and earlier has a misconfiguration vulnerability.
Published 2017-08-11 · Modified
7.5EPSS 0.068
CVE-2017-3111
An issue was discovered in Adobe Experience Manager 6.3, 6.2, 6.1, 6.0. Sensitive tokens are included in http GET requests under certain circumstances.
Published 2017-12-09 · Modified
7.5EPSS 0.068
1 / 32Next →