Campaign
Vendor:
First CVE: Feb 15, 2017 · Active for 9 years
13
Total CVEs
More Total CVEs than 91% of tracked products
2.6
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 71% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Campaign over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 15, 2017
9 years ago
Most Recent CVE
Jun 30, 2026
24 days ago
CVE Severity & Scoring
Campaign13 CVEs
15%
46%
38%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network13 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None12 (92.3%)
Unknown0 (0.0%)
Required1 (7.7%)
Privileges Required
Low1 (7.7%)
High0 (0.0%)
None12 (92.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-48286CRITICAL Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the con | Jun 30, 2026 | 10.0 | 44 | NO | NO |
CVE-2026-48303CRITICAL Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the con | Jun 9, 2026 | 10.0 | 43 | NO | NO |
CVE-2019-7850CRITICAL Adobe Campaign Classic version 18.10.5-8984 and earlier versions have a Command injection vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the conte | Jul 18, 2019 | 9.8 | 26 | NO | NO |
CVE-2021-40745HIGH Adobe Campaign version 21.2.1 (and earlier) is affected by a Path Traversal vulnerability that could lead to reading arbitrary server files. By leveraging an exposed XML file, an u | Nov 17, 2021 | 7.5 | 25 | NO | NO |
CVE-2019-7848HIGH Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Inadequate access control vulnerability. Successful exploitation could lead to Information Disclosure in th | Jul 18, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-7846HIGH Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Improper error handling vulnerability. Successful exploitation could lead to Information Disclosure in the | Jul 18, 2019 | 7.5 | 25 | NO | NO |
CVE-2017-2989CRITICAL Adobe Campaign versions Build 8770 and earlier have an input validation bypass that could be exploited to read, write, or delete data from the Campaign database. | Apr 12, 2017 | 9.1 | 24 | NO | NO |
CVE-2017-2968CRITICAL Adobe Campaign versions 16.4 Build 8724 and earlier have a code injection vulnerability. | Feb 15, 2017 | 9.1 | 23 | NO | NO |
CVE-2022-42343MEDIUM Adobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. | Dec 16, 2022 | 6.5 | 22 | NO | NO |
CVE-2019-7941HIGH Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Information Exposure Through an Error Message vulnerability. Successful exploitation could lead to Informat | Jul 18, 2019 | 7.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Campaign
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.4.3 | 1 | 10.0 | 0.5% | 0 | 0 |