CVE-2026-47970: Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Published Jun 9, 2026
·Updated
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Affected Software
5 affected components
Adobe Adobe Experience Manager<=6.5.24 (LTS SP1, 2026.04)
Adobe Experience Manager<6.5.25.0
Adobe Experience Manager<2026.5.0
Adobe Experience Manager=6.5
Adobe Experience Manager=6.5-sp1
Event History
Jun 9, 2026
CVE Published
via MITRE·04:48 PM
Data Sourced
via MITRE·04:48 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-47970?
CVE-2026-47970 has a medium severity score of 5.4.
2
How do I fix CVE-2026-47970?
To fix CVE-2026-47970, upgrade to Adobe Experience Manager version 6.5.25 or later.
3
What type of vulnerability is CVE-2026-47970?
CVE-2026-47970 is a stored Cross-Site Scripting (XSS) vulnerability.
4
Who can exploit CVE-2026-47970?
CVE-2026-47970 can be exploited by a low-privileged attacker.
5
What impact does CVE-2026-47970 have on users?
CVE-2026-47970 can allow malicious scripts to be executed in a victim's browser.