📦

experience_manager

Vendor: adobe

Actively Exploited 1 CISA KEV List
PoC / Exploits 8 Code Available
Total RCEs 35 Remote Access
Total CVEs 1724 Total Indexed
Avg. EPSS 1.03% Exploit Prob.
Latest CVE CVE-2026-34694 Jun 09

Security Vulnerability Index

Page 117 / 173
6.1 CVSS

Cross-site scripting (XSS) vulnerability in Adobe Experience Manager 5.6.1, 6.0, 6.1, and 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: 1.73%
5.3 CVSS

Adobe Experience Manager 6.0, 6.1, and 6.2 allow attackers to obtain sensitive audit log event information via unspecified vectors.

EPSS: 2.75%
6.1 CVSS

Cross-site scripting (XSS) vulnerability in Adobe Experience Manager 5.6.1, 6.0, and 6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: 1.73%
7.5 CVSS

Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 might allow remote attackers to have an unspecified impact via a crafted serialized Java object.

EPSS: 3.80%
7.5 CVSS
CVE-2016-0957
Exploit Found

Dispatcher before 4.1.5 in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 does not properly implement a URL filter, which allows remote attackers to bypass dispatcher rules via unspecified vectors.

EPSS: 50.71%
7.5 CVSS
CVE-2016-0956
Exploit Found

The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sensitive information via unspecified vectors.

EPSS: 46.19%
6.1 CVSS

Cross-site scripting (XSS) vulnerability in Adobe Experience Manager (AEM) 6.1.0 allows remote authenticated users to inject arbitrary web script or HTML via a folder title field that is mishandled in the Deletion popup dialog.

EPSS: 1.20%