Experience Manager
Vendor:
First CVE: Feb 10, 2016 · Active for 10 years
1,166
Total CVEs
More Total CVEs than 100% of tracked products
106.0
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 15% of tracked products
0.1%
KEV Rate
Higher KEV Rate than 95% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Experience Manager over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 10, 2016
10 years ago
Most Recent CVE
Jul 14, 2026
10 days ago
CVE Severity & Scoring
Experience Manager1,166 CVEs
95%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network1,166 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1,162 (99.7%)
High4 (0.3%)
Unknown0 (0.0%)
User Interaction
None59 (5.1%)
Unknown0 (0.0%)
Required1,107 (94.9%)
Privileges Required
Low1,050 (90.1%)
High13 (1.1%)
None103 (8.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (1166 CVEs).
1,166 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-54253CRITICAL Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this | Aug 5, 2025 | 10.0 | 96 | YES | NO |
CVE-2025-54254HIGH Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary fil | Aug 5, 2025 | 8.6 | 74 | NO | NO |
CVE-2025-49533CRITICAL Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an atta | Jul 8, 2025 | 9.8 | 69 | NO | YES |
CVE-2016-0957HIGH Dispatcher before 4.1.5 in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 does not properly implement a URL filter, which allows remote attackers to bypass dispatcher rules via u | Feb 10, 2016 | 7.5 | 60 | NO | YES |
CVE-2016-0956HIGH The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sensitive information via unspecif | Feb 10, 2016 | 7.5 | 55 | NO | YES |
CVE-2018-5006HIGH Adobe Experience Manager versions 6.4 and earlier have a Server-Side Request Forgery vulnerability. Successful exploitation could lead to sensitive information disclosure. | Jul 20, 2018 | 7.5 | 50 | NO | NO |
CVE-2019-8086HIGH Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitive information disclosure. | Oct 25, 2019 | 7.5 | 42 | NO | YES |
CVE-2026-48259CRITICAL Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-p | Jul 14, 2026 | 9.6 | 40 | NO | NO |
CVE-2026-48359CRITICAL Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the context | Jul 14, 2026 | 9.6 | 40 | NO | NO |
CVE-2019-16469HIGH Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an expression language injection vulnerability. Successful exploitation could lead to sensitive information | Jan 15, 2020 | 7.5 | 40 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (1166 CVEs).
CISA KEV
1 CVE
0.1% of CVEs· 95th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
6 CVEs
0.5% of CVEs· 96th percentile
ExploitDB
1 CVE
0.1% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (1166 CVEs).
Media Mentions
Signals from CVEs in this product scope (1166 CVEs).
Top CNAs Publishing CVEs For Experience Manager
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.5.22.0 | 5 | 5.4 | 0.2% | 0 | 0 |
| 6.5 | 238 | 5.6 | 0.4% | 0 | 3 |
| 6.4.0 | 8 | 6.1 | 2.1% | 0 | 0 |
| 6.4 | 16 | 7.0 | 4.4% | 0 | 1 |
| 6.3.2.1 | 1 | 5.3 | 4.9% | 0 | 0 |
| 6.3.0 | 11 | 6.1 | 2.4% | 0 | 0 |
| 6.3 | 13 | 6.8 | 4.1% | 0 | 1 |
| 6.2.0.0 | 6 | 5.1 | 1.8% | 0 | 0 |
| 6.2.0 | 15 | 6.1 | 2.7% | 0 | 0 |
| 6.2 | 11 | 7.0 | 4.5% | 0 | 1 |
| 6.1.0 | 19 | 6.3 | 7.5% | 0 | 2 |
| 6.1 | 2 | 6.1 | 1.5% | 0 | 0 |
| 6.0.0 | 16 | 6.3 | 8.2% | 0 | 2 |
| 6.0 | 2 | 6.1 | 1.5% | 0 | 0 |
| 5.6.1 | 6 | 6.7 | 17.8% | 0 | 2 |