CVE-2026-75735: Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs low-privileged access and must be able to submit malicious content through vulnerable form fields. Exploitation also requires a victim to browse to a page that displays the affected field.
What is the likely impact on other users?
Malicious JavaScript can run in the victim's browser in the context of the affected application. The supplied vector indicates low confidentiality and integrity impact, no availability impact, and a changed scope.