VendorsAdobeexperience_managerany version
Vulnerabilities

Adobe Experience Manager any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1222CVEs
CVE-2019-16468
Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an user interface injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2020-01-15 · Modified
7.5EPSS 0.026
CVE-2021-21083
Adobe Experience Manager broken access control in DSRPReindexServlet could lead to denial-of-service
Published 2021-06-28 · Modified
7.5EPSS 0.020
CVE-2021-28626
Adobe Experience Manager Improper Authorization at /content/usergenerated
Published 2021-08-24 · Modified
7.5EPSS 0.013
CVE-2021-21084
Adobe Experience Manager stored cross-site scripting vulnerability in resource resolver factory could lead to arbitrary code execution
Published 2021-06-28 · Modified
7.3EPSS 0.018
CVE-2020-9735
Stored XSS in AEM's Content Repository Development Environment
Published 2020-09-10 · Modified
6.8EPSS 0.018
CVE-2020-9736
Stored XSS in AEM's Content Repository Development Environment
Published 2020-09-10 · Modified
6.8EPSS 0.018
CVE-2020-9737
Stored XSS in AEM's Content Repository Development Environment
Published 2020-09-10 · Modified
6.8EPSS 0.017
CVE-2020-9738
Stored XSS in AEM's Content Repository Development Environment
Published 2020-09-10 · Modified
6.8EPSS 0.017
CVE-2019-7953
Adobe Experience Manager version 6.4 and ealier have a Cross-Site Request Forgery vulnerability. Successful exploitation could lead to Sensitive Information disclosure in the context of the current user.
Published 2019-07-18 · Modified
6.5EPSS 0.027
CVE-2025-54249
Adobe Experience Manager | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2025-09-09 · Analyzed
6.5EPSS 0.019
CVE-2021-40712
Adobe Experience Manager Path parameter Improper Input Validation Could Lead To DOS
Published 2021-09-27 · Modified
6.5EPSS 0.017
CVE-2021-43762
Adobe Experience Manager Unicode normalization leads to dispatcher bypass
Published 2022-01-13 · Modified
6.5EPSS 0.016
CVE-2024-43729
Adobe Experience Manager | Improper Authorization (CWE-285)
Published 2024-12-10 · Analyzed
6.5EPSS 0.011
CVE-2025-54247
Adobe Experience Manager | Improper Input Validation (CWE-20)
Published 2025-09-09 · Analyzed
6.5EPSS 0.005
CVE-2025-54246
Adobe Experience Manager | Incorrect Authorization (CWE-863)
Published 2025-09-09 · Analyzed
6.5EPSS 0.004
CVE-2021-28625
Adobe Experience Manager Cross-site Scripting vulnerability in inbox workitem.jsp
Published 2021-08-24 · Modified
6.3EPSS 0.010
CVE-2021-28628
Adobe Experience Manager Cross-site Scripting vulnerability in inbox render.jsp
Published 2021-08-24 · Modified
6.3EPSS 0.010
CVE-2018-5005
Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a Cross-site Scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2018-09-06 · Modified
6.1EPSS 0.039
CVE-2018-12806
Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2018-08-29 · Modified
6.1EPSS 0.039
CVE-2016-7882
Adobe Experience Manager versions 6.2 and earlier have an input validation issue in the WCMDebug filter that could be used in cross-site scripting attacks.
Published 2016-12-15 · Modified
6.1EPSS 0.026
CVE-2016-7884
Adobe Experience Manager versions 6.1 and earlier have an input validation issue in the DAM create assets that could be used in cross-site scripting attacks.
Published 2016-12-15 · Modified
6.1EPSS 0.026
CVE-2020-9647
Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting (dom-based) vulnerability. Successful exploitation could lead to arbitrary javascript execution in the browser.
Published 2020-06-12 · Modified
6.1EPSS 0.024
CVE-2020-9648
Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting vulnerability. Successful exploitation could lead to arbitrary javascript execution in the browser.
Published 2020-06-12 · Modified
6.1EPSS 0.024
CVE-2020-9651
Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting (reflected) vulnerability. Successful exploitation could lead to arbitrary javascript execution in the browser.
Published 2020-06-12 · Modified
6.1EPSS 0.024
CVE-2018-4930
Adobe Experience Manager versions 6.3 and earlier have an exploitable Cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2018-05-19 · Modified
6.1EPSS 0.023
CVE-2018-4931
Adobe Experience Manager versions 6.1 and earlier have an exploitable stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2018-05-19 · Modified
6.1EPSS 0.023
CVE-2018-4929
Adobe Experience Manager versions 6.2 and earlier have an exploitable stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2018-05-19 · Modified
6.1EPSS 0.023
CVE-2019-7955
Adobe Experience Manager version 6.4 and ealier have a Reflected Cross-site Scripting vulnerability. Successful exploitation could lead to Sensitive Information disclosure in the context of the current user.
Published 2019-07-18 · Modified
6.1EPSS 0.021
CVE-2020-9743
HTML injection in AEM's content editor component
Published 2020-09-10 · Modified
6.1EPSS 0.020
CVE-2019-7954
Adobe Experience Manager version 6.4 and ealier have a Stored Cross-site Scripting vulnerability. Successful exploitation could lead to Sensitive Information disclosure in the context of the current user.
Published 2019-07-18 · Modified
6.1EPSS 0.017
CVE-2019-16466
Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2020-01-15 · Modified
6.1EPSS 0.015
CVE-2021-44178
Adobe Experience Manager Reflected XSS in /bin/wcm/contentfinder/page/view.html
Published 2022-01-13 · Modified
6.1EPSS 0.014
CVE-2021-40714
Adobe Experience Manager Reflected Cross Site Scripting via accesskey parameter
Published 2021-09-27 · Modified
6.1EPSS 0.011
CVE-2026-47991
Adobe Experience Manager | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601)
Published 2026-06-09 · Analyzed
6.1EPSS 0.005
CVE-2024-36216
Adobe Experience Manager | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2024-06-13 · Modified
6.1EPSS 0.004
CVE-2025-47049
Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Published 2025-06-10 · Analyzed
6.1EPSS 0.003
CVE-2025-47094
Adobe Experience Manager | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2025-06-10 · Analyzed
6.1EPSS 0.003
CVE-2021-40713
Adobe Experience Manager Improper Certificate Validation Could Lead to Man In The Middle Attack
Published 2021-09-27 · Modified
5.9EPSS 0.010
CVE-2022-28851
AEM Reflected XSS Arbitrary code execution
Published 2022-09-30 · Modified
5.4EPSS 0.368
CVE-2025-54252
Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2025-09-09 · Analyzed
5.4EPSS 0.049
← Prev2 / 31Next →