Vulnerabilities > Adobe > Experience Manager Forms > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-09-10 CVE-2020-9733 Improper Privilege Management vulnerability in Adobe Experience Manager
An AEM java servlet in AEM versions 6.5.5.0 (and below) and 6.4.8.1 (and below) executes with the permissions of a high privileged service user.
network
low complexity
adobe CWE-269
5.0
2020-09-10 CVE-2020-9732 Cross-site Scripting vulnerability in Adobe Experience Manager
The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Sites component.
network
adobe CWE-79
6.0
2019-10-22 CVE-2019-8089 Cross-site Scripting vulnerability in Adobe Experience Manager Forms 6.3/6.4/6.5
Adobe Experience Manager Forms versions 6.3-6.5 have a reflected cross-site scripting vulnerability.
network
adobe CWE-79
4.3
2019-05-29 CVE-2019-7129 Cross-site Scripting vulnerability in Adobe Experience Manager Forms 6.2/6.3/6.4
Adobe Experience Manager Forms versions 6.2, 6.3 and 6.4 have a stored cross-site scripting vulnerability.
network
adobe CWE-79
4.3
2017-05-09 CVE-2017-3067 Information Exposure vulnerability in Adobe Experience Manager Forms 6.0/6.1/6.2
Adobe Experience Manager Forms versions 6.2, 6.1, 6.0 have an information disclosure vulnerability resulting from abuse of the pre-population service in AEM Forms.
network
low complexity
adobe CWE-200
5.0
2016-12-15 CVE-2016-6934 Cross-site Scripting vulnerability in Adobe Experience Manager Forms and Livecycle
Adobe Experience Manager Forms versions 6.2 and earlier, LiveCycle 11.0.1, LiveCycle 10.0.4 have an input validation issue in the PMAdmin module that could be used in cross-site scripting attacks.
network
adobe CWE-79
4.3