CVEs (8)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit...Show more |
Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security mechan...Show more |
1Adobe 2Experience Manager Experience Manager FormsJun 17, 2026 Sep 10, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An AEM java servlet in AEM versions 6.5.5.0 (and below) and 6.4.8.1 (and below) executes with the permissions of a high privileged service user. If exploited, this could lead to read-only access to sensitive data in an A...Show more |
1Adobe 2Experience Manager Experience Manager FormsJun 17, 2026 Sep 10, 2020 N/A· v4 9.0 CRITICAL· v3 6.0 MEDIUM· v2 The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the...Show more |
1Adobe 1Experience Manager Forms Jun 17, 2026 Oct 22, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Adobe Experience Manager Forms versions 6.3-6.5 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure. |
1Adobe 1Experience Manager Forms Jun 17, 2026 May 29, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Adobe Experience Manager Forms versions 6.2, 6.3 and 6.4 have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure. |
1Adobe 1Experience Manager Forms May 13, 2026 May 9, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Adobe Experience Manager Forms versions 6.2, 6.1, 6.0 have an information disclosure vulnerability resulting from abuse of the pre-population service in AEM Forms. |
1Adobe 2Experience Manager Forms LivecycleMay 6, 2026 Dec 15, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Adobe Experience Manager Forms versions 6.2 and earlier, LiveCycle 11.0.1, LiveCycle 10.0.4 have an input validation issue in the PMAdmin module that could be used in cross-site scripting attacks. |