Impact
Adobe Experience Manager versions 6.5.24, LTS SP1, and 2026.04, along with all earlier releases, contain a stored cross‑site scripting flaw that permits a low‑privileged attacker to insert arbitrary script into form fields. When a user accesses a page containing the compromised form, the injected JavaScript runs within the victim’s browser, enabling client‑side compromise.
Affected Systems
The vulnerability exists in Adobe Experience Manager deployments using the identified versions. Administrators should confirm the version of AEM in use and apply the relevant Adobe advisory updates.
Risk and Exploitability
The CVSS score of 5.4 denotes moderate severity. No EPSS score is available, so the likelihood of exploitation is unknown; the flaw is not listed in CISA’s KEV catalog, indicating no widespread exploitation currently. The change of scope suggests that the attack could affect additional components beyond the directly used form.
OpenCVE Enrichment