📦

experience_manager

Vendor: adobe

Actively Exploited 1 CISA KEV List
PoC / Exploits 8 Code Available
Total RCEs 35 Remote Access
Total CVEs 1724 Total Indexed
Avg. EPSS 1.03% Exploit Prob.
Latest CVE CVE-2026-34694 Jun 09

Security Vulnerability Index

Page 116 / 173
6.1 CVSS

An issue was discovered in Adobe Experience Manager 6.3, 6.2, 6.1, 6.0. A cross-site scripting vulnerability in Apache Sling Servlets Post 2.3.20 has been resolved in Adobe Experience Manager.

EPSS: 2.93%
7.5 CVSS

Adobe Experience Manager 6.1 and earlier has a sensitive data exposure vulnerability.

EPSS: 5.25%
9.8 CVSS

Adobe Experience Manager 6.2 and earlier has a malicious file execution vulnerability.

EPSS: 8.62%
7.5 CVSS

Adobe Experience Manager 6.3 and earlier has a misconfiguration vulnerability.

EPSS: 6.80%
8.8 CVSS

Adobe Experience Manager versions 6.2 and earlier have a vulnerability that could be used in Cross-Site Request Forgery attacks.

EPSS: 3.45%
6.1 CVSS

Adobe Experience Manager versions 6.1 and earlier have an input validation issue in the DAM create assets that could be used in cross-site scripting attacks.

EPSS: 2.62%
6.1 CVSS

Adobe Experience Manager version 6.2 has an input validation issue in create Launch wizard that could be used in cross-site scripting attacks.

EPSS: 2.62%
6.1 CVSS

Adobe Experience Manager versions 6.2 and earlier have an input validation issue in the WCMDebug filter that could be used in cross-site scripting attacks.

EPSS: 2.64%
6.1 CVSS

Adobe Experience Manager Forms versions 6.2 and earlier, LiveCycle 11.0.1, LiveCycle 10.0.4 have an input validation issue in the AACComponent that could be used in cross-site scripting attacks.

EPSS: 2.00%
5.3 CVSS

The Backup functionality in Adobe Experience Manager 5.6.1, 6.0, 6.1, and 6.2 allows attackers to obtain sensitive information via unspecified vectors.

EPSS: 2.75%