Stored Cross-Site Scripting Vulnerability in Adobe Experience Manager
CVE-2025-64854

5.4MEDIUM

What is CVE-2025-64854?

Adobe Experience Manager contains a stored Cross-Site Scripting (XSS) vulnerability that can be exploited by attackers with low privileges. By injecting malicious scripts into vulnerable form fields, these attackers could execute harmful JavaScript in the browsers of users who navigate to the page with the compromised fields. This vulnerability may lead to unauthorized actions and data exposure, making it critical for users to take necessary precautions and apply the latest updates.

Affected Version(s)

Adobe Experience Manager 6.5 0 <= 6.5.24

Adobe Experience Manager 6.5 LTS 0

Adobe Experience Manager as a Cloud Service 0 <= 2026.7.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.