Impact
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are vulnerable to a stored cross‑site scripting flaw that allows a low‑privileged attacker to inject malicious JavaScript into form fields. When a victim visits a page containing the injected script, the code executes in the victim’s browser, enabling client‑side compromise such as cookie theft, session hijacking, or execution of additional malicious actions. The flaw is classified as scope‑changed, meaning the script can run for any user who views the affected page, not just the one who submitted the data.
Affected Systems
The affected product is Adobe Experience Manager. Vulnerable versions include 6.5.24, LTS SP1, 2026.04 and all earlier builds. No other vendors or product families are listed as affected.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. EPSS data is not available, and Adobe has not listed this vulnerability in CISA’s KEV catalog. Based on the description, the likely attack vector is local: a non‑admin user can submit a crafted payload to a vulnerable form field. Once the payload is stored, it is rendered indiscriminately for any user who views the affected page, providing an opportunity for client‑side attacks.
OpenCVE Enrichment