Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Experience Manager — Vulnerabilities & Security Advisories 104

All 104 CVE vulnerabilities found in Experience Manager, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for the Experience Manager product, covering a broad spectrum of weakness types and associated security tags. It collects and indexes known security flaws, configuration issues, and logic errors discovered within the software ecosystem. The data encompasses a comprehensive time range, spanning from early historical releases up to the most recent updates, ensuring that both legacy and current vulnerabilities are accounted for in the central repository. By consolidating these records, the platform provides a unified view of the security posture of Experience Manager, eliminating the need to consult multiple disparate sources. Readers can utilize this resource to track a vendor's advisories, understanding the timeline and impact of disclosed issues. Furthermore, users can analyze specific weakness classes to identify common patterns and root causes, such as injection flaws or insecure defaults. The page also allows for a detailed look up of a product's vulnerability history, offering insights into how security has evolved over different versions. This structured approach facilitates better risk assessment and prioritization for security teams managing Experience Manager deployments. The information is presented objectively to support informed decision-making regarding patching, mitigation, and long-term maintenance strategies without bias or promotional language.

Vendor: Adobe Systems Incorporated

CVE IDTitleCVSSSeverityPublished
CVE-2025-34510 Sitecore XM, XC, and XP Post-Auth RCE via Zip Slip CWE-23 8.8 High2025-06-17
CVE-2025-34509 Sitecore XM and XP Hardcoded Credentials CWE-798 7.5 High2025-06-17
CVE-2023-29307 Open Redirect on AEM Target CWE-601 5.4 Medium2023-06-15
CVE-2023-22254 AEM Reflected XSS Arbitrary code execution CWE-79 5.4 Medium2023-03-22
CVE-2023-22252 AEM Reflected XSS Arbitrary code execution CWE-79 5.4 Medium2023-03-22
CVE-2023-22253 AEM Reflected XSS Arbitrary code execution CWE-79 5.4 Medium2023-03-22
CVE-2023-22256 AEM URL Redirection to Untrusted Site Security feature bypass CWE-601 5.4 Medium2023-03-22
CVE-2023-22257 AEM URL Redirection to Untrusted Site Security feature bypass CWE-601 5.4 Medium2023-03-22
CVE-2023-22258 AEM URL Redirection to Untrusted Site Security feature bypass CWE-601 5.4 Medium2023-03-22
CVE-2023-22259 AEM URL Redirection to Untrusted Site Security feature bypass CWE-601 5.4 Medium2023-03-22
CVE-2023-22260 AEM URL Redirection to Untrusted Site Security feature bypass CWE-601 5.4 Medium2023-03-22
CVE-2023-22262 AEM URL Redirection to Untrusted Site Security feature bypass CWE-601 5.4 Medium2023-03-22
CVE-2023-22263 AEM URL Redirection to Untrusted Site Security feature bypass CWE-601 5.4 Medium2023-03-22
CVE-2023-22264 AEM URL Redirection to Untrusted Site Security feature bypass CWE-601 5.4 Medium2023-03-22
CVE-2023-22265 AEM URL Redirection to Untrusted Site Security feature bypass CWE-601 5.4 Medium2023-03-22
CVE-2023-22266 AEM URL Redirection to Untrusted Site Security feature bypass CWE-601 5.4 Medium2023-03-22
CVE-2023-22261 AEM URL Redirection to Untrusted Site Security feature bypass CWE-601 5.4 Medium2023-03-22
CVE-2023-22269 AEM Reflected XSS Arbitrary code execution CWE-79 5.4 Medium2023-03-22
CVE-2023-22271 AEM Weak Cryptography for Passwords Security feature bypass CWE-261 5.3 Medium2023-03-22
CVE-2022-44510 AEM Reflected XSS Arbitrary code execution CWE-79 5.4 Medium2022-12-23
CVE-2022-42365 AEM Reflected XSS Arbitrary code execution CWE-79 5.4 Medium2022-12-21
CVE-2022-42364 AEM Reflected XSS Arbitrary code execution CWE-79 5.4 Medium2022-12-21
CVE-2022-42362 AEM Reflected XSS Arbitrary code execution CWE-79 5.4 Medium2022-12-21
CVE-2022-30679 AEM Reflected XSS Arbitrary code execution CWE-79 5.4 Medium2022-12-21
CVE-2022-42357 AEM Reflected XSS Arbitrary code execution CWE-79 5.4 Medium2022-12-21
CVE-2022-42356 AEM Reflected XSS Arbitrary code execution CWE-79 5.4 Medium2022-12-21
CVE-2022-42354 AEM Reflected XSS Arbitrary code execution CWE-79 5.4 Medium2022-12-21
CVE-2022-42345 AEM Reflected XSS Arbitrary code execution CWE-79 5.4 Medium2022-12-21
CVE-2022-35693 AEM Reflected XSS Arbitrary code execution CWE-79 5.4 Medium2022-12-21
CVE-2022-42346 AEM Reflected XSS Arbitrary code execution CWE-79 5.4 Medium2022-12-21

All 104 known CVE vulnerabilities affecting Experience Manager with full Chinese analysis, references, and POCs where available.