📦 Connect

by Adobe

🔍 What is Connect?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-49553

CRITICAL CVSS 9.3 Oct 14, 2025

Adobe Connect versions 12.9 and earlier contain a DOM-based Cross-Site Scripting vulnerability that allows attackers to execute malicious JavaScript in victims' browsers. Exploitation requires user in...

CVE-2025-27203

CRITICAL CVSS 9.6 Jul 8, 2025

Adobe Connect versions 24.0 and earlier contain a deserialization vulnerability that allows attackers to execute arbitrary code on affected systems. Exploitation requires user interaction, such as tri...

CVE-2025-43567

CRITICAL CVSS 9.3 May 13, 2025

Adobe Connect versions 12.8 and earlier contain a reflected Cross-Site Scripting (XSS) vulnerability where attackers can inject malicious scripts into vulnerable form fields. When victims browse to pa...

CVE-2024-54032

CRITICAL CVSS 9.3 Dec 10, 2024

Adobe Connect versions 12.6, 11.4.7 and earlier contain a stored Cross-Site Scripting (XSS) vulnerability where attackers can inject malicious scripts into form fields. When users visit pages with the...

CVE-2024-54036

CRITICAL CVSS 9.3 Dec 10, 2024

This stored Cross-Site Scripting (XSS) vulnerability in Adobe Connect allows attackers to inject malicious JavaScript into vulnerable form fields. When victims visit pages containing the injected scri...

CVE-2023-4662

CRITICAL CVSS 9.8 Sep 15, 2023

This vulnerability allows remote attackers to execute arbitrary code on Saphira Connect systems by exploiting unnecessary privilege execution. It affects all Saphira Connect installations before versi...

CVE-2021-40719

CRITICAL CVSS 9.8 Oct 21, 2021

CVE-2021-40719 is a critical deserialization vulnerability in Adobe Connect that allows attackers to execute arbitrary code on affected servers by sending malicious AMF messages. This affects Adobe Co...

CVE-2025-49552

HIGH CVSS 7.3 Oct 14, 2025

Adobe Connect versions 12.9 and earlier contain a DOM-based XSS vulnerability that allows high-privileged attackers to execute malicious scripts in victims' browsers. Exploitation requires user intera...

CVE-2023-4664

HIGH CVSS 8.8 Sep 15, 2023

Saphira Connect versions before 9 have incorrect default permissions that allow local users to escalate privileges. This vulnerability affects all systems running vulnerable versions of Saphira Connec...

CVE-2025-30314

MEDIUM CVSS 6.1 May 13, 2025

Adobe Connect versions 12.8 and earlier contain a stored Cross-Site Scripting vulnerability where attackers can inject malicious JavaScript into form fields. When users visit pages containing the comp...

CVE-2025-30316

MEDIUM CVSS 5.4 May 13, 2025

Adobe Connect versions 12.8 and earlier contain a stored Cross-Site Scripting vulnerability that allows low-privileged attackers to inject malicious JavaScript into form fields. When victims visit pag...

CVE-2024-54046

MEDIUM CVSS 6.1 Dec 10, 2024

This reflected Cross-Site Scripting (XSS) vulnerability in Adobe Connect allows attackers to execute malicious JavaScript in victims' browsers by tricking them into clicking specially crafted URLs. Un...

CVE-2024-54048

MEDIUM CVSS 6.1 Dec 10, 2024

This reflected Cross-Site Scripting (XSS) vulnerability in Adobe Connect allows attackers to execute malicious JavaScript in victims' browsers by tricking them into clicking specially crafted URLs. Un...

CVE-2024-54050

MEDIUM CVSS 6.1 Dec 10, 2024

Adobe Connect versions 12.6, 11.4.7 and earlier contain an open redirect vulnerability (CWE-601) that allows attackers to redirect users to malicious websites. This requires user interaction such as c...

CVE-2024-54038

MEDIUM CVSS 4.3 Dec 10, 2024

CVE-2024-54038 is an improper access control vulnerability in Adobe Connect that allows low-privileged attackers to bypass security measures. This affects Adobe Connect versions 12.6, 11.4.7 and earli...

CVE-2024-54040

MEDIUM CVSS 5.4 Dec 10, 2024

This stored Cross-Site Scripting (XSS) vulnerability in Adobe Connect allows attackers to inject malicious JavaScript into vulnerable form fields. When users visit pages containing the compromised fie...

CVE-2024-54042

MEDIUM CVSS 6.1 Dec 10, 2024

This reflected Cross-Site Scripting (XSS) vulnerability in Adobe Connect allows unauthenticated attackers to execute malicious JavaScript in victims' browsers by tricking them into visiting specially ...

CVE-2024-54044

MEDIUM CVSS 6.1 Dec 10, 2024

This reflected Cross-Site Scripting (XSS) vulnerability in Adobe Connect allows unauthenticated attackers to execute malicious JavaScript in victims' browsers by tricking them into clicking specially ...