CVE-2026-48280: Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48280?
CVE-2026-48280 has a medium severity rating of 5.4.
How can I mitigate CVE-2026-48280?
Mitigation for CVE-2026-48280 includes upgrading to Adobe Experience Manager version 6.5.25 or later.
What impact does CVE-2026-48280 have on systems?
CVE-2026-48280 can allow attackers to execute malicious JavaScript in the context of the victim's browser.
What versions of Adobe Experience Manager are affected by CVE-2026-48280?
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by CVE-2026-48280.
Is CVE-2026-48280 a critical vulnerability?
CVE-2026-48280 is not classified as critical; it has a medium severity level.