XSS Vulnerability in Adobe Experience Manager Affects Multiple Versions
CVE-2025-47050

5.4MEDIUM

Key Information:

Vendor

Adobe

Vendor
CVE Published:
10 June 2025

What is CVE-2025-47050?

Adobe Experience Manager versions 6.5.22 and earlier are susceptible to a stored cross-site scripting (XSS) vulnerability. Attackers with low privileges can exploit this flaw to inject harmful scripts into form fields, leading to the execution of malicious JavaScript in the browsers of users who access the compromised page. This exploitation underlines the essential need for users to ensure their installations are up to date and to follow best security practices.

Affected Version(s)

Adobe Experience Manager 0 <= 6.5.22

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.