Impact
Adobe Experience Manager is affected by a stored Cross‑Site Scripting vulnerability that allows a low‑privileged attacker to insert malicious JavaScript into vulnerable form fields. When a victim loads a page containing the altered field, the embedded script executes in the victim’s browser, potentially exfiltrating data or executing actions on the victim’s behalf. The vulnerability also features a scope change, indicating that an attacker could affect a broader portion of the system than initially intended.
Affected Systems
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and all earlier releases are vulnerable. Any instance of these versions that has publicly accessible forms may be susceptible.
Risk and Exploitability
The CVSS score of 5.4 places the issue in the moderate severity range, and the EPSS score is not reported but the vulnerability is not listed in CISA’s KEV catalog. Despite the moderate score, exploitation is relatively straightforward: a low‑privileged user can submit crafted input through a known form, triggering client‑side script execution. The scope change increases the potential impact once exploit conditions are met.
OpenCVE Enrichment