Stored XSS Vulnerability in Adobe Experience Manager by Adobe
CVE-2026-27265
5.4MEDIUM
What is CVE-2026-27265?
A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager that affects versions 6.5.23 and earlier. This security issue permits low-privileged attackers to inject malicious scripts into specific form fields, exploiting the vulnerability when users access the affected page. As a result, arbitrary JavaScript could be executed in the browser of any user navigating to the compromised area, posing significant risks to user data and system integrity.
Affected Version(s)
Adobe Experience Manager 0 <= 6.5.23