DOM-based Cross-Site Scripting Vulnerability in Adobe Experience Manager
CVE-2026-48254
5.4MEDIUM
Key Information:
- Vendor
Adobe
- Status
- Vendor
- CVE Published:
- 14 July 2026
What is CVE-2026-48254?
Adobe Experience Manager is susceptible to a DOM-based Cross-Site Scripting (XSS) vulnerability that allows attackers to inject and execute malicious JavaScript code within the victim's web browser. This exploitation requires user interaction; specifically, victims must visit a specially crafted webpage designed to manipulate the DOM environment. The implications of this vulnerability can compromise the security and integrity of user data.
Affected Version(s)
Adobe Experience Manager 6.5 0 <= 6.5.25
Adobe Experience Manager 6.5 0 <= 6.5.25
Adobe Experience Manager 6.5 LTS 0