VendorsAdobeexperience_managerall versions
Vulnerabilities

Adobe Experience Manager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1265CVEs
CVE-2017-3110
Adobe Experience Manager 6.1 and earlier has a sensitive data exposure vulnerability.
Published 2017-08-11 · Modified
7.5EPSS 0.053
CVE-2018-12809
Adobe Experience Manager versions 6.4 and earlier have a Server-Side Request Forgery vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2018-07-20 · Modified
7.5EPSS 0.049
CVE-2018-5004
Adobe Experience Manager versions 6.2 and 6.3 have a Server-Side Request Forgery vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2018-07-20 · Modified
7.5EPSS 0.042
CVE-2020-9733
Sensitive information disclosure possible in AEM
Published 2020-09-10 · Modified
7.5EPSS 0.038
CVE-2019-8087
Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2019-10-25 · Modified
7.5EPSS 0.036
CVE-2019-8081
Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have an authentication bypass vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2019-10-25 · Modified
7.5EPSS 0.033
CVE-2020-9643
Adobe Experience Manager versions 6.5 and earlier have a server-side request forgery (ssrf) vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2020-06-12 · Modified
7.5EPSS 0.033
CVE-2020-9645
Adobe Experience Manager versions 6.5 and earlier have a blind server-side request forgery (ssrf) vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2020-06-12 · Modified
7.5EPSS 0.033
CVE-2020-3741
Adobe Experience Manager versions 6.5, and 6.4 have an uncontrolled resource consumption vulnerability. Successful exploitation could lead to denial-of-service.
Published 2020-02-13 · Modified
7.5EPSS 0.032
CVE-2019-8082
Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2019-10-25 · Modified
7.5EPSS 0.032
CVE-2020-3769
Adobe Experience Manager versions 6.5 and earlier have a server-side request forgery (ssrf) vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2020-03-25 · Modified
7.5EPSS 0.029
CVE-2019-16468
Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an user interface injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2020-01-15 · Modified
7.5EPSS 0.026
CVE-2021-21083
Adobe Experience Manager broken access control in DSRPReindexServlet could lead to denial-of-service
Published 2021-06-28 · Modified
7.5EPSS 0.020
CVE-2021-28626
Adobe Experience Manager Improper Authorization at /content/usergenerated
Published 2021-08-24 · Modified
7.5EPSS 0.013
CVE-2021-21084
Adobe Experience Manager stored cross-site scripting vulnerability in resource resolver factory could lead to arbitrary code execution
Published 2021-06-28 · Modified
7.3EPSS 0.018
CVE-2020-9735
Stored XSS in AEM's Content Repository Development Environment
Published 2020-09-10 · Modified
6.8EPSS 0.018
CVE-2020-9736
Stored XSS in AEM's Content Repository Development Environment
Published 2020-09-10 · Modified
6.8EPSS 0.018
CVE-2020-9737
Stored XSS in AEM's Content Repository Development Environment
Published 2020-09-10 · Modified
6.8EPSS 0.017
CVE-2020-9738
Stored XSS in AEM's Content Repository Development Environment
Published 2020-09-10 · Modified
6.8EPSS 0.017
CVE-2019-7953
Adobe Experience Manager version 6.4 and ealier have a Cross-Site Request Forgery vulnerability. Successful exploitation could lead to Sensitive Information disclosure in the context of the current user.
Published 2019-07-18 · Modified
6.5EPSS 0.027
CVE-2019-8234
Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a cross-site request forgery vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2019-10-25 · Modified
6.5EPSS 0.021
CVE-2025-54249
Adobe Experience Manager | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2025-09-09 · Analyzed
6.5EPSS 0.019
CVE-2021-40712
Adobe Experience Manager Path parameter Improper Input Validation Could Lead To DOS
Published 2021-09-27 · Modified
6.5EPSS 0.017
CVE-2021-43762
Adobe Experience Manager Unicode normalization leads to dispatcher bypass
Published 2022-01-13 · Modified
6.5EPSS 0.016
CVE-2024-43729
Adobe Experience Manager | Improper Authorization (CWE-285)
Published 2024-12-10 · Analyzed
6.5EPSS 0.011
CVE-2025-54247
Adobe Experience Manager | Improper Input Validation (CWE-20)
Published 2025-09-09 · Analyzed
6.5EPSS 0.005
CVE-2025-54246
Adobe Experience Manager | Incorrect Authorization (CWE-863)
Published 2025-09-09 · Analyzed
6.5EPSS 0.004
CVE-2021-28625
Adobe Experience Manager Cross-site Scripting vulnerability in inbox workitem.jsp
Published 2021-08-24 · Modified
6.3EPSS 0.010
CVE-2021-28628
Adobe Experience Manager Cross-site Scripting vulnerability in inbox render.jsp
Published 2021-08-24 · Modified
6.3EPSS 0.010
CVE-2018-4876
Adobe Experience Manager versions 6.3, 6.2, and 6.1 are vulnerable to cross-site scripting via a bypass of the Sling XSSAPI#getValidHref function.
Published 2018-02-27 · Modified
6.1EPSS 0.040
CVE-2018-5005
Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a Cross-site Scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2018-09-06 · Modified
6.1EPSS 0.039
CVE-2018-12806
Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2018-08-29 · Modified
6.1EPSS 0.039
CVE-2018-4875
Adobe Experience Manager versions 6.1 and 6.0 are vulnerable to a reflected cross-site scripting vulnerability related to the handling of malicious content embedded in image files uploaded to the DAM.
Published 2018-02-27 · Modified
6.1EPSS 0.038
CVE-2017-3109
An issue was discovered in Adobe Experience Manager 6.3, 6.2, 6.1, 6.0. Adobe Experience Manager has a reflected cross-site scripting vulnerability in the HtmlRendererServlet.
Published 2017-12-09 · Modified
6.1EPSS 0.029
CVE-2017-11296
An issue was discovered in Adobe Experience Manager 6.3, 6.2, 6.1, 6.0. A cross-site scripting vulnerability in Apache Sling Servlets Post 2.3.20 has been resolved in Adobe Experience Manager.
Published 2017-12-09 · Modified
6.1EPSS 0.029
CVE-2016-7882
Adobe Experience Manager versions 6.2 and earlier have an input validation issue in the WCMDebug filter that could be used in cross-site scripting attacks.
Published 2016-12-15 · Modified
6.1EPSS 0.026
CVE-2016-7883
Adobe Experience Manager version 6.2 has an input validation issue in create Launch wizard that could be used in cross-site scripting attacks.
Published 2016-12-15 · Modified
6.1EPSS 0.026
CVE-2016-7884
Adobe Experience Manager versions 6.1 and earlier have an input validation issue in the DAM create assets that could be used in cross-site scripting attacks.
Published 2016-12-15 · Modified
6.1EPSS 0.026
CVE-2020-9647
Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting (dom-based) vulnerability. Successful exploitation could lead to arbitrary javascript execution in the browser.
Published 2020-06-12 · Modified
6.1EPSS 0.024
CVE-2020-9648
Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting vulnerability. Successful exploitation could lead to arbitrary javascript execution in the browser.
Published 2020-06-12 · Modified
6.1EPSS 0.024
← Prev2 / 32Next →