VendorsAdobeexperience_manager_formsall versions
Vulnerabilities

Adobe Experience Manager Forms

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2025-54253
Adobe Experience Manager | Incorrect Authorization (CWE-863)
Published 2025-08-05 · Analyzed
10.0KEVEPSS 0.880
CVE-2020-9732
Stored XSS in AEM Sites Components
Published 2020-09-10 · Modified
9.0EPSS 0.028
CVE-2025-54254
Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
Published 2025-08-05 · Analyzed
8.6EPSS 0.772
CVE-2017-3067
Adobe Experience Manager Forms versions 6.2, 6.1, 6.0 have an information disclosure vulnerability resulting from abuse of the pre-population service in AEM Forms.
Published 2017-05-09 · Modified
7.5EPSS 0.048
CVE-2020-9733
Sensitive information disclosure possible in AEM
Published 2020-09-10 · Modified
7.5EPSS 0.038
CVE-2016-6934
Adobe Experience Manager Forms versions 6.2 and earlier, LiveCycle 11.0.1, LiveCycle 10.0.4 have an input validation issue in the PMAdmin module that could be used in cross-site scripting attacks.
Published 2016-12-15 · Modified
6.1EPSS 0.026
CVE-2019-7129
Adobe Experience Manager Forms versions 6.2, 6.3 and 6.4 have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2019-05-29 · Modified
6.1EPSS 0.016
CVE-2019-8089
Adobe Experience Manager Forms versions 6.3-6.5 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
Published 2019-10-22 · Modified
6.1EPSS 0.015