Filtered by vendor Adobe
Subscriptions
Filtered by product Experience Manager
Subscriptions
Total
920 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2022-44465 | 1 Adobe | 2 Experience Manager, Experience Manager Cloud Service | 2025-04-23 | 5.4 Medium |
Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. | ||||
CVE-2022-44466 | 1 Adobe | 2 Experience Manager, Experience Manager Cloud Service | 2025-04-23 | 5.4 Medium |
Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. | ||||
CVE-2022-44467 | 1 Adobe | 2 Experience Manager, Experience Manager Cloud Service | 2025-04-23 | 5.4 Medium |
Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. | ||||
CVE-2022-44470 | 1 Adobe | 2 Experience Manager, Experience Manager Cloud Service | 2025-04-23 | 5.4 Medium |
Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. | ||||
CVE-2022-44471 | 1 Adobe | 2 Experience Manager, Experience Manager Cloud Service | 2025-04-23 | 5.4 Medium |
Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. | ||||
CVE-2022-44474 | 1 Adobe | 2 Experience Manager, Experience Manager Cloud Service | 2025-04-23 | 5.4 Medium |
Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. | ||||
CVE-2022-44488 | 1 Adobe | 2 Experience Manager, Experience Manager Cloud Service | 2025-04-23 | 3.5 Low |
Adobe Experience Manager version 6.5.14 (and earlier) is affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction. | ||||
CVE-2022-44510 | 1 Adobe | 2 Experience Manager, Experience Manager Cloud Service | 2025-04-23 | 5.4 Medium |
Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. | ||||
CVE-2017-3107 | 1 Adobe | 1 Experience Manager | 2025-04-20 | N/A |
Adobe Experience Manager 6.3 and earlier has a misconfiguration vulnerability. | ||||
CVE-2017-3110 | 1 Adobe | 1 Experience Manager | 2025-04-20 | N/A |
Adobe Experience Manager 6.1 and earlier has a sensitive data exposure vulnerability. | ||||
CVE-2017-3109 | 1 Adobe | 1 Experience Manager | 2025-04-20 | N/A |
An issue was discovered in Adobe Experience Manager 6.3, 6.2, 6.1, 6.0. Adobe Experience Manager has a reflected cross-site scripting vulnerability in the HtmlRendererServlet. | ||||
CVE-2017-3108 | 1 Adobe | 1 Experience Manager | 2025-04-20 | N/A |
Adobe Experience Manager 6.2 and earlier has a malicious file execution vulnerability. | ||||
CVE-2017-3111 | 1 Adobe | 1 Experience Manager | 2025-04-20 | N/A |
An issue was discovered in Adobe Experience Manager 6.3, 6.2, 6.1, 6.0. Sensitive tokens are included in http GET requests under certain circumstances. | ||||
CVE-2017-11296 | 1 Adobe | 1 Experience Manager | 2025-04-20 | N/A |
An issue was discovered in Adobe Experience Manager 6.3, 6.2, 6.1, 6.0. A cross-site scripting vulnerability in Apache Sling Servlets Post 2.3.20 has been resolved in Adobe Experience Manager. | ||||
CVE-2024-53967 | 1 Adobe | 1 Experience Manager | 2025-04-14 | 5.4 Medium |
Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code in the context of the victim's browser session. By manipulating the DOM environment in the victim's browser, a low privileged attacker can inject malicious scripts that are executed by the victim's browser. Exploitation of this issue requires user interaction, typically in the form of following a malicious link. | ||||
CVE-2024-53968 | 1 Adobe | 1 Experience Manager | 2025-04-14 | 5.4 Medium |
Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code in the context of the victim's browser session. By manipulating the DOM environment in the victim's browser, a low privileged attacker can inject malicious scripts that are executed by the victim's browser. Exploitation of this issue requires user interaction, typically in the form of following a malicious link. | ||||
CVE-2024-53969 | 1 Adobe | 1 Experience Manager | 2025-04-14 | 5.4 Medium |
Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code in the context of the victim's browser session. By manipulating the DOM environment in the victim's browser, a low privileged attacker can inject malicious scripts that are executed by the victim's browser. Exploitation of this issue requires user interaction, typically in the form of following a malicious link. | ||||
CVE-2024-53970 | 1 Adobe | 1 Experience Manager | 2025-04-14 | 5.4 Medium |
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. | ||||
CVE-2016-0957 | 4 Adobe, Apple, Linux and 1 more | 5 Dispatcher, Experience Manager, Mac Os X and 2 more | 2025-04-12 | N/A |
Dispatcher before 4.1.5 in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 does not properly implement a URL filter, which allows remote attackers to bypass dispatcher rules via unspecified vectors. | ||||
CVE-2016-7885 | 1 Adobe | 1 Experience Manager | 2025-04-12 | N/A |
Adobe Experience Manager versions 6.2 and earlier have a vulnerability that could be used in Cross-Site Request Forgery attacks. |