Adobe Experience Manager 存在一个基于 DOM 的跨站脚本(XSS)漏洞。攻击者可以通过操纵 DOM 环境,在受害者的浏览器上下文中执行恶意的 JavaScript 代码来利用此问题。利用该漏洞需要用户交互,即受害者必须访问一个构造好的网页。漏洞的影响范围(Scope)发生了变化。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Adobe | Adobe Experience Manager as a Cloud Service | 0 ~ 2026.7.0 | - |
|
| Adobe | Adobe Experience Manager 6.5 LTS | 0 ~ SP2 | - |
|
| Adobe | Adobe Experience Manager 6.5 | 0 ~ 6.5.24 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82004 | 10.0 CRITICAL | Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS C |
| CVE-2026-48273 | 9.9 CRITICAL | ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval In |
| CVE-2026-19232 | 9.9 CRITICAL | Adobe Experience Manager | Incorrect Authorization (CWE-863) |
| CVE-2026-76201 | 9.3 CRITICAL | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-76200 | 9.3 CRITICAL | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-75746 | 9.1 CRITICAL | ColdFusion | Improper Neutralization of Special Elements used in an SQL Command ('SQL Inje |
| CVE-2026-81996 | 8.8 HIGH | Acrobat Reader | Incorrect Authorization (CWE-863) |
| CVE-2026-77111 | 8.7 HIGH | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-76190 | 8.6 HIGH | ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval In |
| CVE-2026-77774 | 8.6 HIGH | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-77109 | 8.6 HIGH | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-75990 | 8.6 HIGH | Illustrator | Incorrect Authorization (CWE-863) |
| CVE-2026-76199 | 8.6 HIGH | Photoshop Desktop | Uncontrolled Search Path Element (CWE-427) |
| CVE-2026-75991 | 8.6 HIGH | Illustrator | Improper Input Validation (CWE-20) |
| CVE-2026-75993 | 8.5 HIGH | ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79) |
| CVE-2026-75999 | 8.4 HIGH | ColdFusion | Improper Input Validation (CWE-20) |
| CVE-2026-76191 | 8.2 HIGH | Animate | Improper Control of Generation of Code ('Code Injection') (CWE-94) |
| CVE-2026-81994 | 8.2 HIGH | Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Proto |
| CVE-2026-76202 | 8.2 HIGH | Adobe Commerce | Incorrect Authorization (CWE-863) |
| CVE-2026-81983 | 7.8 HIGH | Acrobat Reader | Out-of-bounds Write (CWE-787) |
Showing top 20 of 167 CVEs. View all on vendor page → →
No comments yet