← Back to browse · API

CVE-2021-40722

Severity
CRITICAL
CVSS
9.8
EPSS
0.03273
Risk score
40.35
CISA KEV
No
PoC
No
Published
2022-01-13
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2021-27887, GHSA-7H8F-9M99-6CFG
Products
Sitecore:Experience Manager unspecified ≤6.5.10.0, Sitecore:Experience Manager unspecified ≤None
Sources
euvd EUVD-2021-27887

Description

AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) injection vulnerability that could be abused by an attacker to achieve RCE.

References