Impact
Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting flaw classified as CWE‑79. The flaw permits an attacker to craft URLs or embed malicious content that, when a victim’s browser renders the page, causes arbitrary JavaScript to run in the victim’s browser context. This can lead to malicious code execution within the victim’s browser.
Affected Systems
The affected product is Adobe Experience Manager. Versions 6.5.24, the LTS SP1 release, the 2026.04 release, and all earlier versions are impacted. The flaw exists in all configurations of the product that process user supplied data in the DOM.
Risk and Exploitability
The CVSS score is 5.4, indicating moderate risk. No EPSS score is published, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires user interaction; an attacker must entice a victim to visit a maliciously crafted webpage or click a link. Once the victim loads the page, the DOM manipulation triggers the execution of malicious JavaScript. The impact is limited to the victim’s browser context.
OpenCVE Enrichment