CVE-2025-64854: Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Published Sep 8, 2026
·Updated
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Affected Software
1 affected component
Adobe Adobe Experience Manager
Event History
Sep 8, 2026
CVE Published
via MITRE·07:56 PM
Data Sourced
via MITRE·07:56 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access and interaction are required for exploitation?
An attacker needs low-privileged access to inject malicious script into a vulnerable form field. A victim must then browse to a page containing that field for the script to execute in the victim's browser.
2
What is the likely impact if the issue is exploited?
The attacker can cause malicious JavaScript to run in the victim's browser. The provided severity data indicates low confidentiality and integrity impact, no availability impact, and a changed scope.