Description
Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage.
Published: 2026-04-14
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting (DOM‑based)
Action: Patch
AI Analysis

Impact

Adobe Experience Manager versions 6.5.24, FP11.7 and earlier contain a DOM‑based Cross‑Site Scripting vulnerability that allows an attacker to inject malicious JavaScript executed in the victim’s browser. When a user visits a crafted page, the attacker‑controlled code runs with the victim’s privileges, potentially enabling session hijacking, data theft or other malicious actions performed in the context of the user’s session.

Affected Systems

The affected product is Adobe Experience Manager. All releases up through version 6.5.24 and Pulse Fix 11.7, as well as earlier releases, are vulnerable. Systems running a later release are not known to be impacted.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity, and no EPSS data or KEV listing is available. Exploitation requires user interaction with a maliciously crafted webpage; delivery could occur through email links, social engineering or compromised content. While the vulnerability does not provide remote code execution on the server, it undermines the confidentiality and integrity of the victim’s session and data and thus represents a moderate risk under the current circumstances.

Generated by OpenCVE AI on April 14, 2026 at 21:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Adobe Experience Manager to a version that is not affected (for example, 6.5.25 or later).
  • If an immediate upgrade is not feasible, implement a strict Content Security Policy that blocks inline script execution and limits approved script sources.
  • Sanitize or properly encode any user‑supplied data that may be reflected in the DOM to prevent injections.
  • Review all third‑party or external resources that could be loaded into pages to ensure they are trustworthy.
  • Monitor web traffic and user activity for attempts to access suspicious URLs until the vulnerability is fully remediated.

Generated by OpenCVE AI on April 14, 2026 at 21:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Apr 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe experience Manager
Adobe experience Manager Screens
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager_screens:*:*:*:*:-:*:*:*
Vendors & Products Adobe experience Manager
Adobe experience Manager Screens

Wed, 15 Apr 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Experience Manager
Vendors & Products Adobe
Adobe adobe Experience Manager

Tue, 14 Apr 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Apr 2026 18:45:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage.
Title Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Adobe Experience Manager Experience Manager Experience Manager Screens
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-04-14T18:53:03.853Z

Reserved: 2026-03-30T17:30:36.490Z

Link: CVE-2026-34624

cve-icon Vulnrichment

Updated: 2026-04-14T18:52:58.353Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-14T19:16:38.087

Modified: 2026-04-15T19:42:05.727

Link: CVE-2026-34624

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-15T14:41:09Z

Weaknesses