Cross-Site Scripting Vulnerability in Adobe Experience Manager
CVE-2026-48255
5.4MEDIUM
Key Information:
- Vendor
Adobe
- Status
- Vendor
- CVE Published:
- 14 July 2026
What is CVE-2026-48255?
A significant vulnerability exists in Adobe Experience Manager that allows for DOM-based Cross-Site Scripting (XSS) attacks. By manipulating the DOM environment, an attacker can execute harmful JavaScript in a victim's browser. This exploitation necessitates that the victim interacts with a specially crafted webpage, effectively changing the scope of potential attacks and increasing the risk for users.
Affected Version(s)
Adobe Experience Manager 6.5 0 <= 6.5.25
Adobe Experience Manager 6.5 0 <= 6.5.25
Adobe Experience Manager 6.5 LTS 0