Bloomreach's vulnerability footprint centers on its Experience Manager product, a content management and personalization platform used in digital commerce and marketing contexts. The recurring exposure reflects common web-application weaknesses including cross-site request forgery, cross-site scripting, injection flaws, and missing authorization controls that arise in server-side content delivery and form-handling paths. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bloomreach over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-14987HIGH An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows remote attackers to execute arbitrary code because there is a mishandling of the cap | Mar 11, 2021 | 7.2 | 24 | NO | NO |
CVE-2020-14989MEDIUM An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows CSRF if the attacker uses GET where POST was intended. | Mar 11, 2021 | 6.5 | 21 | NO | NO |
CVE-2020-14988MEDIUM An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows XSS in the login page via the loginmessage parameter, the text editor via the src at | Mar 11, 2021 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bloomreach.
Media articles that mention a CVE ID that affects a product developed by Bloomreach — matched by CVE ID, not by vendor name.