5.4
CVE-2025-64588
- EPSS 0.27%
- Veröffentlicht 08.09.2026 19:55:56
- Zuletzt bearbeitet 11.09.2026 14:04:36
- Erkennungen
Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Experience Manager Update - SwEdition lts Version < 6.5
Adobe ≫ Experience Manager SwEdition - Version < 6.5.25.0
Adobe ≫ Experience Manager SwEdition aem_cloud_service Version < 2026.8.0
Adobe ≫ Experience Manager Version 6.5 Update - SwEdition lts
Adobe ≫ Experience Manager Version 6.5 Update sp1 SwEdition lts
Adobe ≫ Experience Manager Version 6.5 Update sp2 SwEdition lts
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.27% | 0.191 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Adobe | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html