VendorsAdobeexperience_managerall versions
Vulnerabilities

Adobe Experience Manager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1265CVEs
CVE-2020-9651
Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting (reflected) vulnerability. Successful exploitation could lead to arbitrary javascript execution in the browser.
Published 2020-06-12 · Modified
6.1EPSS 0.024
CVE-2018-15972
Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2018-10-17 · Modified
6.1EPSS 0.024
CVE-2018-4929
Adobe Experience Manager versions 6.2 and earlier have an exploitable stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2018-05-19 · Modified
6.1EPSS 0.024
CVE-2018-4930
Adobe Experience Manager versions 6.3 and earlier have an exploitable Cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2018-05-19 · Modified
6.1EPSS 0.024
CVE-2018-4931
Adobe Experience Manager versions 6.1 and earlier have an exploitable stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2018-05-19 · Modified
6.1EPSS 0.024
CVE-2018-15973
Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2018-10-17 · Modified
6.1EPSS 0.024
CVE-2019-7955
Adobe Experience Manager version 6.4 and ealier have a Reflected Cross-site Scripting vulnerability. Successful exploitation could lead to Sensitive Information disclosure in the context of the current user.
Published 2019-07-18 · Modified
6.1EPSS 0.021
CVE-2016-6933
Adobe Experience Manager Forms versions 6.2 and earlier, LiveCycle 11.0.1, LiveCycle 10.0.4 have an input validation issue in the AACComponent that could be used in cross-site scripting attacks.
Published 2016-12-15 · Modified
6.1EPSS 0.020
CVE-2020-9743
HTML injection in AEM's content editor component
Published 2020-09-10 · Modified
6.1EPSS 0.020
CVE-2018-15970
Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2018-10-17 · Modified
6.1EPSS 0.019
CVE-2018-15971
Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2018-10-17 · Modified
6.1EPSS 0.019
CVE-2018-19727
Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2019-01-28 · Modified
6.1EPSS 0.019
CVE-2018-19724
Adobe Experience Manager Forms versions 6.2, 6.3 and 6.4 have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2019-01-28 · Modified
6.1EPSS 0.019
CVE-2018-19726
Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2019-01-28 · Modified
6.1EPSS 0.019
CVE-2018-15969
Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2018-10-17 · Modified
6.1EPSS 0.019
CVE-2019-8080
Adobe Experience Manager versions 6.4 and 6.3 have a stored cross site scripting vulnerability. Successful exploitation could lead to privilege escalation.
Published 2019-10-24 · Modified
6.1EPSS 0.018
CVE-2016-0955
Cross-site scripting (XSS) vulnerability in Adobe Experience Manager (AEM) 6.1.0 allows remote authenticated users to inject arbitrary web script or HTML via a folder title field that is mishandled in the Deletion popup dialog.
Published 2016-02-10 · Modified
6.1EPSS 0.017
CVE-2016-4170
Cross-site scripting (XSS) vulnerability in Adobe Experience Manager 5.6.1, 6.0, 6.1, and 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2016-08-09 · Modified
6.1EPSS 0.017
CVE-2016-4168
Cross-site scripting (XSS) vulnerability in Adobe Experience Manager 5.6.1, 6.0, and 6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2016-08-09 · Modified
6.1EPSS 0.017
CVE-2019-7954
Adobe Experience Manager version 6.4 and ealier have a Stored Cross-site Scripting vulnerability. Successful exploitation could lead to Sensitive Information disclosure in the context of the current user.
Published 2019-07-18 · Modified
6.1EPSS 0.017
CVE-2019-8078
Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a reflected cross site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2019-10-24 · Modified
6.1EPSS 0.016
CVE-2019-16466
Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2020-01-15 · Modified
6.1EPSS 0.015
CVE-2019-8079
Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a stored cross site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2019-10-24 · Modified
6.1EPSS 0.015
CVE-2019-16467
Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2020-01-15 · Modified
6.1EPSS 0.015
CVE-2019-8083
Adobe Experience Manager versions 6.5, 6.4 and 6.3 have a cross site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2019-10-25 · Modified
6.1EPSS 0.015
CVE-2019-8085
Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a reflected cross site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2019-10-25 · Modified
6.1EPSS 0.015
CVE-2019-8084
Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a reflected cross site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2019-10-25 · Modified
6.1EPSS 0.015
CVE-2021-44178
Adobe Experience Manager Reflected XSS in /bin/wcm/contentfinder/page/view.html
Published 2022-01-13 · Modified
6.1EPSS 0.014
CVE-2021-40714
Adobe Experience Manager Reflected Cross Site Scripting via accesskey parameter
Published 2021-09-27 · Modified
6.1EPSS 0.011
CVE-2026-47991
Adobe Experience Manager | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601)
Published 2026-06-09 · Analyzed
6.1EPSS 0.005
CVE-2024-36216
Adobe Experience Manager | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2024-06-13 · Modified
6.1EPSS 0.004
CVE-2025-47049
Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Published 2025-06-10 · Analyzed
6.1EPSS 0.003
CVE-2025-47094
Adobe Experience Manager | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2025-06-10 · Analyzed
6.1EPSS 0.003
CVE-2021-40713
Adobe Experience Manager Improper Certificate Validation Could Lead to Man In The Middle Attack
Published 2021-09-27 · Modified
5.9EPSS 0.010
CVE-2022-28851
AEM Reflected XSS Arbitrary code execution
Published 2022-09-30 · Modified
5.4EPSS 0.368
CVE-2025-54252
Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2025-09-09 · Analyzed
5.4EPSS 0.049
CVE-2020-9644
Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting (stored) vulnerability. Successful exploitation could lead to arbitrary javascript execution in the browser.
Published 2020-06-12 · Modified
5.4EPSS 0.018
CVE-2021-40711
Adobe Experience Manager Stored Cross-Site Scripting Could Lead to Arbitrary Code Execution
Published 2021-09-27 · Modified
5.4EPSS 0.015
CVE-2024-43738
Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Published 2024-12-10 · Analyzed
5.4EPSS 0.009
CVE-2024-43733
Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Published 2024-12-10 · Analyzed
5.4EPSS 0.009
← Prev3 / 32Next →