Description
Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a specially crafted web page.
Published: 2026-04-14
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: DOM-based Cross‑Site Scripting (XSS)
Action: Apply patch
AI Analysis

Impact

This vulnerability allows the execution of arbitrary JavaScript within the victim’s browser by manipulating the DOM environment. The attacker can only succeed if the user visits a specially crafted web page, after which the malicious script runs with the user’s browser privileges, enabling actions such as data theft or session hijacking.

Affected Systems

Adobe Experience Manager versions 6.5.24, FP11.7 and all earlier releases are affected. The product is Adobe Experience Manager provided by Adobe.

Risk and Exploitability

The CVSS base score of 5.4 indicates a moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires user interaction in the browser, so the attack vector is client‑side. While no exploit information is present in the provided data, the requirement of user interaction limits the ease of attack but still poses a risk to users who may unintentionally visit malicious content.

Generated by OpenCVE AI on April 14, 2026 at 21:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify the Adobe Experience Manager version on each deployed instance and confirm whether it matches the affected releases.
  • Consult the Adobe security advisory linked in the references for the official patch or upgrade instructions.
  • Apply the vendor‑provided patch or upgrade to a non‑affected version as soon as possible.
  • As a temporary measure, restrict or disable features that load untrusted content and monitor browser consoles for unexpected JavaScript.
  • Keep monitoring Adobe security advisories for further updates.

Generated by OpenCVE AI on April 14, 2026 at 21:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Apr 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe experience Manager
Adobe experience Manager Screens
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager_screens:*:*:*:*:-:*:*:*
Vendors & Products Adobe experience Manager
Adobe experience Manager Screens

Wed, 15 Apr 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Experience Manager
Vendors & Products Adobe
Adobe adobe Experience Manager

Tue, 14 Apr 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Apr 2026 18:45:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a specially crafted web page.
Title Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Adobe Experience Manager Experience Manager Experience Manager Screens
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-04-14T18:59:02.939Z

Reserved: 2026-03-30T17:30:36.490Z

Link: CVE-2026-34623

cve-icon Vulnrichment

Updated: 2026-04-14T18:58:51.729Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-14T19:16:37.903

Modified: 2026-04-15T19:41:53.107

Link: CVE-2026-34623

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-15T14:41:09Z

Weaknesses