Adobe

Experience Manager Forms

8 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Media report Exploit
  • EPSS 0.95%
  • Published 05.08.2025 16:53:40
  • Last modified 13.08.2025 18:56:02

Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploit...

Media report
  • EPSS 0.1%
  • Published 05.08.2025 16:53:39
  • Last modified 02.10.2025 19:17:17

Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access ...

  • EPSS 0.49%
  • Published 10.09.2020 17:15:36
  • Last modified 21.11.2024 05:41:10

An AEM java servlet in AEM versions 6.5.5.0 (and below) and 6.4.8.1 (and below) executes with the permissions of a high privileged service user. If exploited, this could lead to read-only access to sensitive data in an AEM repository.

  • EPSS 0.95%
  • Published 10.09.2020 17:15:35
  • Last modified 21.11.2024 05:41:10

The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Sites component. These script...

  • EPSS 1.64%
  • Published 22.10.2019 21:15:10
  • Last modified 21.11.2024 04:49:15

Adobe Experience Manager Forms versions 6.3-6.5 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

  • EPSS 1.38%
  • Published 29.05.2019 18:29:01
  • Last modified 21.11.2024 04:47:37

Adobe Experience Manager Forms versions 6.2, 6.3 and 6.4 have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

  • EPSS 4.53%
  • Published 09.05.2017 16:29:00
  • Last modified 20.04.2025 01:37:25

Adobe Experience Manager Forms versions 6.2, 6.1, 6.0 have an information disclosure vulnerability resulting from abuse of the pre-population service in AEM Forms.

  • EPSS 0.9%
  • Published 15.12.2016 06:59:27
  • Last modified 12.04.2025 10:46:40

Adobe Experience Manager Forms versions 6.2 and earlier, LiveCycle 11.0.1, LiveCycle 10.0.4 have an input validation issue in the PMAdmin module that could be used in cross-site scripting attacks.