Adobe
Adobe Experience Manager Forms: vulnerabilidades y CVE
Adobe Experience Manager Forms tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas2
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-54253 | Crítica (10) | 88% | ⚠ Explotación activa | 5 ago 2025 | Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-54254 | Alta (8.6) | 77% | — | 5 ago 2025 | Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could… |
| CVE-2025-54253 | Crítica (10) | 88% | ⚠ Explotación activa | 5 ago 2025 | Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security… |
| CVE-2020-9733 | Alta (7.5) | 3.8% | — | 10 sept 2020 | An AEM java servlet in AEM versions 6.5.5.0 (and below) and 6.4.8.1 (and below) executes with the permissions of a high privileged service user. If exploited, this could lead to read-only access to sensitive data in an… |
| CVE-2020-9732 | Crítica (9) | 2.8% | — | 10 sept 2020 | The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with… |
| CVE-2019-8089 | Media (6.1) | 1.5% | — | 22 oct 2019 | Adobe Experience Manager Forms versions 6.3-6.5 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure. |
| CVE-2019-7129 | Media (6.1) | 1.6% | — | 29 may 2019 | Adobe Experience Manager Forms versions 6.2, 6.3 and 6.4 have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure. |
| CVE-2017-3067 | Alta (7.5) | 4.8% | — | 9 may 2017 | Adobe Experience Manager Forms versions 6.2, 6.1, 6.0 have an information disclosure vulnerability resulting from abuse of the pre-population service in AEM Forms. |
| CVE-2016-6934 | Media (6.1) | 2.6% | — | 15 dic 2016 | Adobe Experience Manager Forms versions 6.2 and earlier, LiveCycle 11.0.1, LiveCycle 10.0.4 have an input validation issue in the PMAdmin module that could be used in cross-site scripting attacks. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.