📦

experience_manager

Vendor: adobe

Actively Exploited 1 CISA KEV List
PoC / Exploits 8 Code Available
Total RCEs 35 Remote Access
Total CVEs 1724 Total Indexed
Avg. EPSS 1.03% Exploit Prob.
Latest CVE CVE-2026-34694 Jun 09

Security Vulnerability Index

Page 115 / 173
7.5 CVSS

Adobe Experience Manager versions 6.4 and earlier have a Server-Side Request Forgery vulnerability. Successful exploitation could lead to sensitive information disclosure.

EPSS: 53.75%
7.5 CVSS

Adobe Experience Manager versions 6.2 and 6.3 have a Server-Side Request Forgery vulnerability. Successful exploitation could lead to sensitive information disclosure.

EPSS: 4.27%
7.5 CVSS

Adobe Experience Manager versions 6.4 and earlier have a Server-Side Request Forgery vulnerability. Successful exploitation could lead to sensitive information disclosure.

EPSS: 4.95%
6.1 CVSS

Adobe Experience Manager versions 6.1 and earlier have an exploitable stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

EPSS: 1.88%
6.1 CVSS

Adobe Experience Manager versions 6.3 and earlier have an exploitable Cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

EPSS: 1.88%
6.1 CVSS

Adobe Experience Manager versions 6.2 and earlier have an exploitable stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

EPSS: 1.88%
6.1 CVSS

Adobe Experience Manager versions 6.3, 6.2, and 6.1 are vulnerable to cross-site scripting via a bypass of the Sling XSSAPI#getValidHref function.

EPSS: 4.60%
6.1 CVSS

Adobe Experience Manager versions 6.1 and 6.0 are vulnerable to a reflected cross-site scripting vulnerability related to the handling of malicious content embedded in image files uploaded to the DAM.

EPSS: 3.43%
7.5 CVSS

An issue was discovered in Adobe Experience Manager 6.3, 6.2, 6.1, 6.0. Sensitive tokens are included in http GET requests under certain circumstances.

EPSS: 6.80%
6.1 CVSS

An issue was discovered in Adobe Experience Manager 6.3, 6.2, 6.1, 6.0. Adobe Experience Manager has a reflected cross-site scripting vulnerability in the HtmlRendererServlet.

EPSS: 2.93%