Vulnerabilities > Adobe > Experience Manager > 6.5.8.0

DATE CVE VULNERABILITY TITLE RISK
2022-01-13 CVE-2021-43764 Cross-site Scripting vulnerability in Adobe Experience Manager
AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields.
network
adobe CWE-79
3.5
2022-01-13 CVE-2021-43765 Cross-site Scripting vulnerability in Adobe Experience Manager
AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields.
network
adobe CWE-79
4.3
2022-01-13 CVE-2021-44176 Cross-site Scripting vulnerability in Adobe Experience Manager
AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields.
network
adobe CWE-79
4.3
2022-01-13 CVE-2021-44177 Cross-site Scripting vulnerability in Adobe Experience Manager
AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields.
network
adobe CWE-79
4.3
2022-01-13 CVE-2021-44178 Cross-site Scripting vulnerability in Adobe Experience Manager
AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a reflected Cross-Site Scripting (XSS) vulnerability via the itemResourceType parameter.
network
adobe CWE-79
4.3
2021-09-27 CVE-2021-40711 Cross-site Scripting vulnerability in Adobe Experience Manager
Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a stored XSS vulnerability when creating Content Fragments.
network
adobe CWE-79
3.5
2021-09-27 CVE-2021-40712 Improper Input Validation vulnerability in Adobe Experience Manager
Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a improper input validation vulnerability via the path parameter.
network
low complexity
adobe CWE-20
4.0
2021-09-27 CVE-2021-40713 Improper Certificate Validation vulnerability in Adobe Experience Manager
Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a improper certificate validation vulnerability in the cold storage component.
network
adobe CWE-295
4.3
2021-09-27 CVE-2021-40714 Cross-site Scripting vulnerability in Adobe Experience Manager
Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability via the accesskey parameter.
network
adobe CWE-79
4.3
2021-08-24 CVE-2021-28626 Unspecified vulnerability in Adobe Experience Manager
Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by an Improper Authorization vulnerability allowing users to create nodes under a location.
network
low complexity
adobe
5.0