Description
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Published: 2026-09-08
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

A low‑privileged attacker may insert malicious JavaScript into vulnerable form fields of Adobe Experience Manager. The script is stored and later executed in any victim’s browser when they view the page that contains the input field. This can lead to theft of session data, credential compromise, or further manipulation of the affected system. The vulnerability’s scope is changed, indicating that the attacker can affect the system on the same level as the authenticated user who submitted the input.

Affected Systems

Adobe Experience Manager versions 6.5 and 6.5 LTS, as well as the Cloud Service offering. The vulnerability is present in all forms and components that allow user input without proper sanitization.

Risk and Exploitability

The CVSS score of 5.4 categorizes this issue as medium severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting that active exploitation at this time is not documented. The likely attack vector involves submitting a crafted payload in a form field that is later rendered on a page viewed by other users. Because the vulnerability is stored, the attack can persist across sessions, making the risk significant for organisations that rely heavily on user‑generated content.

Generated by OpenCVE AI on September 9, 2026 at 13:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Experience Manager security update for 6.5, 6.5 LTS, or the Cloud Service. The patch removes the input sanitization flaw that allows stored XSS.
  • Configure form fields to perform strict server‑side input validation and escape or strip all potential script content before storing it. This aligns with CWE‑79 mitigation best practices.
  • Deploy a Content Security Policy that blocks inline script execution and limits executable resources to trusted origins, reducing the impact of any remaining stored scripts.

Generated by OpenCVE AI on September 9, 2026 at 13:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:*:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*
Vendors & Products Adobe
Adobe experience Manager

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-10T15:01:52.597Z

Reserved: 2025-11-05T22:53:10.939Z

Link: CVE-2025-64588

cve-icon Vulnrichment

Updated: 2026-09-09T16:41:59.464Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:17:26.187

Modified: 2026-09-11T14:04:36.843

Link: CVE-2025-64588

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T13:15:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')