CVE-2021-21009High· 8.6▾ TwilightAdobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and earlier), 20.1.3 (and earlier), 19.2.3 (and earlier) and 19.1.7 (and earlier) are affected by a server-side request forgery (SSRF) vulnerability. Su…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.3 · likelihood 0.6 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 24.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
3.2%
Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and earlier), 20.1.3 (and earlier), 19.2.3 (and earlier) and 19.1.7 (and earlier) are affected by a server-side request forgery (SSRF) vulnerability. Successful exploitation could allow an attacker to use the Campaign instance to issue unauthorized requests to internal or external resources.
campaign < 19.1.8campaign >= 19.2, < 19.2.4campaign >= 20.1, < 20.1.4campaign >= 20.2, < 20.2.4campaign >= 20.3, < 20.3.3Upgrade past the affected range:
campaign 20.3.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-82443Critical· 9.6Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation
CVE-2026-82013Critical· 9.9Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation
CVE-2026-83660Critical· 9.9Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation
CVE-2026-47938Critical· 10.0Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation
CVE-2022-42343Medium· 6.5Adobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read
CVE-2025-68616High· 7.5WeasyPrint helps web developers to create PDF documents