CVE-2026-47953: Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs low-privileged access and must be able to submit malicious content into a vulnerable form field. Exploitation also requires a victim to browse the page containing that stored content.
What is the likely impact on a victim?
Malicious JavaScript can execute in the victim's browser. The affected versions indicate low confidentiality and integrity impact, with no availability impact, and the impact scope is changed.
Which deployments are known to be affected?
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04, and earlier are identified as affected. The provided information does not state whether vulnerable form fields are enabled or exposed in a default configuration.