Description
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Published: 2026-09-08
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting (XSS) that allows execution of arbitrary JavaScript in a victim’s browser
Action: Patch and mitigate
AI Analysis

Impact

The vulnerability is a stored XSS flaw in Adobe Experience Manager that lets an attacker who has low privileges inject malicious JavaScript into form fields. When a victim later opens the affected page, the injected script runs in the victim’s browser context, potentially compromising the victim’s data, hijacking sessions, or executing further attacks. The flaw involves a change of scope, indicating that it can affect the entire web application beyond the originally affected component.

Affected Systems

Adobe Experience Manager versions 6.5, 6.5 LTS, and the Cloud Service are vulnerable. Any deployment that includes these editions must be checked for the presence of the affected form fields.

Risk and Exploitability

The CVSS score of 5.4 classifies the vulnerability as medium severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw by submitting crafted input to the vulnerable form, which is then stored and reflected in pages viewed by other users. Based on the description, it is inferred that the attacker would initially use a low‑privileged account to submit the malicious input. Because the flaw requires only low privileges to inject malicious content, the risk to users is significant, but no widespread exploitation information is reported at this time.

Generated by OpenCVE AI on September 9, 2026 at 13:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Adobe security patch for CVE‑2025‑64610 as described in Adobe’s advisory.
  • Implement server‑side input validation or sanitization for all affected form fields to strip or encode any potential script content.
  • Continuously monitor user activity for signs of injected scripts and enforce browser security headers such as Content‑Security‑Policy to reduce the impact of any unpatched data.

Generated by OpenCVE AI on September 9, 2026 at 13:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:*:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*
Vendors & Products Adobe
Adobe experience Manager

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-09T13:21:44.681Z

Reserved: 2025-11-05T22:53:10.942Z

Link: CVE-2025-64610

cve-icon Vulnrichment

Updated: 2026-09-09T13:21:41.418Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:17:26.427

Modified: 2026-09-11T13:39:30.937

Link: CVE-2025-64610

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T13:15:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')