Stored Cross-Site Scripting Vulnerability in Adobe Experience Manager
CVE-2025-64854
5.4MEDIUM
Key Information:
- Vendor
Adobe
- Status
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2025-64854?
Adobe Experience Manager contains a stored Cross-Site Scripting (XSS) vulnerability that can be exploited by attackers with low privileges. By injecting malicious scripts into vulnerable form fields, these attackers could execute harmful JavaScript in the browsers of users who navigate to the page with the compromised fields. This vulnerability may lead to unauthorized actions and data exposure, making it critical for users to take necessary precautions and apply the latest updates.
Affected Version(s)
Adobe Experience Manager 6.5 0 <= 6.5.24
Adobe Experience Manager 6.5 LTS 0
Adobe Experience Manager as a Cloud Service 0 <= 2026.7.0