Vulnerabilities > Adobe > Experience Manager > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-09-16 CVE-2022-35664 Cross-site Scripting vulnerability in Adobe Experience Manager
Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability.
network
low complexity
adobe CWE-79
5.4
2022-01-13 CVE-2021-43761 Cross-site Scripting vulnerability in Adobe products
AEM's Cloud Service offering, as well as versions 6.5.7.0 (and below), 6.4.8.3 (and below) and 6.3.3.8 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields.
network
low complexity
adobe CWE-79
5.4
2022-01-13 CVE-2021-43762 Improper Input Validation vulnerability in Adobe products
AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a dispatcher bypass vulnerability that could be abused to evade security controls.
network
low complexity
adobe CWE-20
6.5
2022-01-13 CVE-2021-43764 Cross-site Scripting vulnerability in Adobe products
AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields.
network
low complexity
adobe CWE-79
5.4
2022-01-13 CVE-2021-43765 Cross-site Scripting vulnerability in Adobe products
AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields.
network
low complexity
adobe CWE-79
6.1
2022-01-13 CVE-2021-44176 Cross-site Scripting vulnerability in Adobe products
AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields.
network
low complexity
adobe CWE-79
6.1
2022-01-13 CVE-2021-44177 Cross-site Scripting vulnerability in Adobe products
AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields.
network
low complexity
adobe CWE-79
6.1
2022-01-13 CVE-2021-44178 Cross-site Scripting vulnerability in Adobe products
AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a reflected Cross-Site Scripting (XSS) vulnerability via the itemResourceType parameter.
network
low complexity
adobe CWE-79
6.1
2021-09-27 CVE-2021-40711 Cross-site Scripting vulnerability in Adobe Experience Manager
Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a stored XSS vulnerability when creating Content Fragments.
network
low complexity
adobe CWE-79
5.4
2021-09-27 CVE-2021-40712 Improper Input Validation vulnerability in Adobe Experience Manager
Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a improper input validation vulnerability via the path parameter.
network
low complexity
adobe CWE-20
6.5