Experience Manager

Vendor:

First CVE: Feb 10, 2016 · Active for 10 years

1,166
Total CVEs
More Total CVEs than 100% of tracked products
106.0
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 15% of tracked products
0.1%
KEV Rate
Higher KEV Rate than 95% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Experience Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 10, 2016
10 years ago
Most Recent CVE
Jul 14, 2026
10 days ago

CVE Severity & Scoring

Experience Manager1,166 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network1,166 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1,162 (99.7%)
High4 (0.3%)
Unknown0 (0.0%)
User Interaction
None59 (5.1%)
Unknown0 (0.0%)
Required1,107 (94.9%)
Privileges Required
Low1,050 (90.1%)
High13 (1.1%)
None103 (8.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (1166 CVEs).

1,166 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this
Aug 5, 202510.096YESNO
Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary fil
Aug 5, 20258.674NONO
Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an atta
Jul 8, 20259.869NOYES
Dispatcher before 4.1.5 in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 does not properly implement a URL filter, which allows remote attackers to bypass dispatcher rules via u
Feb 10, 20167.560NOYES
The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sensitive information via unspecif
Feb 10, 20167.555NOYES
Adobe Experience Manager versions 6.4 and earlier have a Server-Side Request Forgery vulnerability. Successful exploitation could lead to sensitive information disclosure.
Jul 20, 20187.550NONO
Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
Oct 25, 20197.542NOYES
Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-p
Jul 14, 20269.640NONO
Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the context
Jul 14, 20269.640NONO
Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an expression language injection vulnerability. Successful exploitation could lead to sensitive information
Jan 15, 20207.540NOYES

Exploit Exposure

Signals from CVEs in this product scope (1166 CVEs).

CISA KEV
1 CVE
0.1% of CVEs· 95th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
6 CVEs
0.5% of CVEs· 96th percentile
ExploitDB
1 CVE
0.1% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (1166 CVEs).

Media Mentions

Signals from CVEs in this product scope (1166 CVEs).

Top CNAs Publishing CVEs For Experience Manager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.5.22.055.40.2%00
6.52385.60.4%03
6.4.086.12.1%00
6.4167.04.4%01
6.3.2.115.34.9%00
6.3.0116.12.4%00
6.3136.84.1%01
6.2.0.065.11.8%00
6.2.0156.12.7%00
6.2117.04.5%01
6.1.0196.37.5%02
6.126.11.5%00
6.0.0166.38.2%02
6.026.11.5%00
5.6.166.717.8%02