Description
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Published: 2026-03-11
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

Adobe Experience Manager versions 6.5.23 and earlier contain a stored XSS vulnerability (CWE‑79). The flaw allows a low‑privileged attacker to submit malicious JavaScript payloads through vulnerable form fields; the payload is then persisted and rendered to any user who accesses the affected page. The injected script executes in the context of the victim’s browser, enabling client‑side attacks such as session‑cookie theft, defacement of the site, phishing or malware delivery. The vulnerability does not provide any server‑side code‑execution or denial‑of‑service capability.

Affected Systems

All Adobe Experience Manager installations running version 6.5.23 or older are affected. This includes the on‑premises 6.5.23 release, the 6.5 LTS build, the SP1 build, and any AEM Cloud Service deployments preceding 6.5.24. The supplied CPE strings confirm that any product matching these identifiers contains the vulnerability.

Risk and Exploitability

The CVSS v3 score of 5.4 indicates a moderate severity impact. The EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in CISA’s KEV catalog, implying no publicly known exploits at this time. An attacker only needs the ability to submit data through a form; no elevated privileges are prerequisite. The stored payload is rendered to any user who views the affected page, making the risk primarily client‑side and potentially allowing credential theft or further phishing once a victim’s browser is compromised.

Generated by OpenCVE AI on March 17, 2026 at 17:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Adobe Experience Manager to a version newer than 6.5.23 or apply the vendor‑released security fix for affected releases.
  • Restrict write permissions on form fields that accept input from low‑privileged users to prevent new malicious content from being stored.
  • Implement server‑side input validation and sanitization to strip dangerous scripts before persisting data.
  • Add a Content‑Security‑Policy header to mitigate the impact of any remaining stored scripts.
  • Monitor Adobe security advisories for further updates and verify that patched deployments are functioning correctly.

Generated by OpenCVE AI on March 17, 2026 at 17:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 11 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 11 Mar 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
Vendors & Products Adobe experience Manager

Wed, 11 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Experience Manager
Vendors & Products Adobe
Adobe adobe Experience Manager

Wed, 11 Mar 2026 01:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Title Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Adobe Experience Manager Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-03-11T13:38:42.751Z

Reserved: 2026-02-18T22:02:41.383Z

Link: CVE-2026-27248

cve-icon Vulnrichment

Updated: 2026-03-11T13:30:59.688Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-11T01:16:54.870

Modified: 2026-03-11T15:20:42.143

Link: CVE-2026-27248

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-20T14:33:36Z

Weaknesses