Description
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Published: 2026-09-08
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting (CWE‑79)
Action: Apply Patch
AI Analysis

Impact

Adobe Experience Manager is vulnerable to a stored Cross‑Site Scripting (XSS) flaw where a low‑privileged attacker can inject malicious JavaScript into form fields that are subsequently rendered to other users. Attackers can exploit the flaw by submitting crafted content in vulnerable fields, and the malicious script will execute in the victim’s browser when they view the page containing the injected content. Because the vulnerability changes scope, an attacker who initially had limited access could elevate their impact to affect other users or system components that render the stored content.

Affected Systems

Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service are affected. No specific sub‑versions are listed; anyone running these products should verify if the flaw applies to their installation.

Risk and Exploitability

With a CVSS score of 5.4, the vulnerability has moderate severity. The EPSS score is not available, and the vulnerability is not cataloged in CISA’s KEV list. The attack vector is inferred to be local or remote depending on the attacker’s ability to submit content to the vulnerable form; the exploit requires the attacker to be able to create or modify content. Once injected, the script runs in the victim’s browser, leading to data theft, credential compromise, or further attacks. Because it is a stored XSS, multiple users may be impacted, and the compromised content can persist across sessions, making mitigation important.

Generated by OpenCVE AI on September 9, 2026 at 12:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the security update for Adobe Experience Manager that resolves the stored XSS issue, following the vendor’s guidance in the advisory.
  • If a patch cannot be applied immediately, block or limit the use of the vulnerable form fields and ensure only trusted users have permission to submit content.
  • Enable strict content sanitization and HTML encoding for all data stored and rendered by AEM to prevent execution of injected scripts.
  • Conduct an audit of exposed form fields and templates to verify that no unsanitized content can be stored or displayed.

Generated by OpenCVE AI on September 9, 2026 at 12:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:*:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*
Vendors & Products Adobe
Adobe experience Manager

Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-11T21:06:40.287Z

Reserved: 2025-11-11T22:48:38.843Z

Link: CVE-2025-64868

cve-icon Vulnrichment

Updated: 2026-09-11T21:06:22.764Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:17:27.157

Modified: 2026-09-11T21:17:08.093

Link: CVE-2025-64868

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T12:45:10Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')