CVE-2025-30314: Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79)
Published May 13, 2025
·Updated
Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Affected Software
2 affected components
Adobe Connect<12.8
Adobe Connect<12.9
Event History
May 13, 2025
CVE Published
via MITRE·08:32 PM
Data Sourced
via MITRE·08:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-30314?
CVE-2025-30314 is classified as a high severity stored Cross-Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2025-30314?
To fix CVE-2025-30314, upgrade to Adobe Connect version 12.9 or later.
3
What versions of Adobe Connect are affected by CVE-2025-30314?
Adobe Connect versions 12.8 and earlier are affected by CVE-2025-30314.
4
What type of vulnerability is CVE-2025-30314?
CVE-2025-30314 is a stored Cross-Site Scripting (XSS) vulnerability.
5
What could an attacker do with CVE-2025-30314?
An attacker could inject malicious JavaScript into vulnerable form fields, which may execute in a victim's browser.