Description
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Published: 2026-06-09
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stored Cross‑Site Scripting vulnerability allows a low‑privileged attacker to inject malicious JavaScript into form fields that are subsequently rendered and executed in a victim’s browser when they visit the affected page. The attack can potentially compromise confidential information, hijack user sessions, and deface content. The vulnerability’s scope change indicates that the XSS payload may execute with higher privileges than the attacker’s initial level, expanding the damage range.

Affected Systems

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and any earlier releases are affected.

Risk and Exploitability

The CVSS score of 5.4 signifies a moderate risk level. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation is not currently documented. However, because the flaw is stored and can be triggered by a low‑privileged user, it poses a notable risk to all users of affected versions, especially in environments where users can submit form data. Exploitation requires the attacker to create or modify a form entry that contains malicious script, which is then stored and later served to any visitor.

Generated by OpenCVE AI on June 9, 2026 at 20:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a patched version of Adobe Experience Manager (6.5.25 or later)
  • Implement input validation or sanitization on all form fields to escape or strip HTML/JavaScript before storage
  • Disable or remove the vulnerable form fields if no immediate patch is available

Generated by OpenCVE AI on June 9, 2026 at 20:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 09 Jun 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Experience Manager
Vendors & Products Adobe
Adobe adobe Experience Manager

Tue, 09 Jun 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Adobe Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-06-09T18:37:44.900Z

Reserved: 2026-05-20T15:50:31.365Z

Link: CVE-2026-47975

cve-icon Vulnrichment

Updated: 2026-06-09T18:37:30.407Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-06-09T17:17:40.467

Modified: 2026-06-09T19:30:24.713

Link: CVE-2026-47975

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-09T23:30:05Z

Weaknesses