← Back

Experience Manager

experience_manager

Vendor: Adobe • 1,166 CVEs

CVEs (1,166)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Adobe
1Experience Manager
May 6, 2026
Aug 9, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Adobe Experience Manager 6.0, 6.1, and 6.2 allow attackers to obtain sensitive audit log event information via unspecified vectors.
1Adobe
1Experience Manager
May 6, 2026
Aug 9, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Adobe Experience Manager 5.6.1, 6.0, and 6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Adobe
1Experience Manager
May 6, 2026
Feb 10, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 might allow remote attackers to have an unspecified impact via a crafted serialized Java object.
1Adobe
2Dispatcher
Experience Manager
May 6, 2026
Feb 10, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Dispatcher before 4.1.5 in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 does not properly implement a URL filter, which allows remote attackers to bypass dispatcher rules via unspecified vectors.
2Adobe
Apache
2Experience Manager
Sling
May 6, 2026
Feb 10, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sensitive information via unspecified vectors.
1Adobe
1Experience Manager
May 6, 2026
Feb 10, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Adobe Experience Manager (AEM) 6.1.0 allows remote authenticated users to inject arbitrary web script or HTML via a folder title field that is mishandled in the Deletion popup...Show more
Cross-site scripting (XSS) vulnerability in Adobe Experience Manager (AEM) 6.1.0 allows remote authenticated users to inject arbitrary web script or HTML via a folder title field that is mishandled in the Deletion popup dialog.Show less