Experience Manager Cloud Service

Vendor:

First CVE: Dec 10, 2020 · Active for 5 years

183
Total CVEs
More Total CVEs than 99% of tracked products
45.8
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 14% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Experience Manager Cloud Service over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 10, 2020
5 years ago
Most Recent CVE
Dec 15, 2023
955 days ago

CVE Severity & Scoring

Experience Manager Cloud Service183 CVEs
All CVEs352,727 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network183 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low182 (99.5%)
High1 (0.5%)
Unknown0 (0.0%)
User Interaction
None5 (2.7%)
Unknown0 (0.0%)
Required178 (97.3%)
Privileges Required
Low175 (95.6%)
High0 (0.0%)
None8 (4.4%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (183 CVEs).

183 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) injection vulnerability that could be abused by an attacker t
Jan 13, 20229.830NONO
AEM's Cloud Service offering, as well as version 6.5.6.0 (and below), are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to injec
Dec 10, 20209.028NONO
AEM's Cloud Service offering, as well as versions 6.5.7.0 (and below), 6.4.8.3 (and below) and 6.3.3.8 (and below) are affected by an Improper Access Control vulnerability. An unau
Jun 28, 20217.524NONO
AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a dispatcher bypass vulnerability that could be abused to evade security controls. Sensitive a
Jan 13, 20226.522NONO
Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim
Dec 22, 20225.421NONO
Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim
Dec 19, 20225.421NONO
AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a reflected Cross-Site Scripting (XSS) vulnerability via the itemResourceType parameter. If an
Jan 13, 20226.121NONO
AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to injec
Jan 13, 20226.121NONO
AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to injec
Jan 13, 20226.121NONO
AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to injec
Jan 13, 20226.121NONO

Exploit Exposure

Signals from CVEs in this product scope (183 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (183 CVEs).

Media Mentions

Signals from CVEs in this product scope (183 CVEs).

Top CNAs Publishing CVEs For Experience Manager Cloud Service

Top CWEs

Versions

No cataloged versions.