Cross-Site Request Forgery Vulnerability in Adobe Dreamweaver
CVE-2025-54256

8.6HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
9 September 2025

What is CVE-2025-54256?

Adobe Dreamweaver Desktop versions 21.5 and earlier are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability. This security flaw enables an attacker to execute arbitrary code in the context of the current user by enticing them to click on a malicious link. Successful exploitation of this vulnerability relies on user interaction, which alters the operational scope and poses significant risks to affected users.

Affected Version(s)

Dreamweaver Desktop 0 <= 21.5

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-54256 : Cross-Site Request Forgery Vulnerability in Adobe Dreamweaver