Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Metrics
Affected Vendors & Products
References
History
Fri, 11 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Adobe
Adobe experience Manager |
|
| CPEs | cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:* cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:* cpe:2.3:a:adobe:experience_manager:*:-:*:*:lts:*:*:* cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:* cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:* cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:* |
|
| Vendors & Products |
Adobe
Adobe experience Manager |
Tue, 08 Sep 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | |
| Title | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: adobe
Published: 2026-09-08T19:56:38.902Z
Updated: 2026-09-10T21:00:28.189Z
Reserved: 2025-11-11T22:48:38.835Z
Link: CVE-2025-64854
No data.
Status : Analyzed
Published: 2026-09-08T20:17:26.923
Modified: 2026-09-11T14:11:28.337
Link: CVE-2025-64854
No data.