Junglewise Threat Intelligence

CVE-2025-64588: Adobe Experience Manager stored XSS in form fields

CVE-2025-64588 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager is a web-based content management and digital asset platform used by enterprises to build and manage websites and customer experiences. The vulnerability allows a low-privileged user to inject malicious scripts into form fields, which execute in the browsers of other users who view those pages. This could lead to session hijacking, credential theft, or unauthorized actions performed on behalf of affected users.

Technical details

This is a stored (persistent) cross-site scripting (XSS) vulnerability in Adobe Experience Manager's form handling. A low-privileged attacker can inject malicious JavaScript into vulnerable form fields, which is then stored in the application and executed in the browsers of other users when they view pages containing the affected field. The vulnerability changes security scope, meaning it can affect components beyond the form field itself. No special network access is required beyond normal AEM access, though the attacker must have form modification privileges. The vulnerability has been assigned CVE-2025-64588 with a CVSS score of 5.4 (medium severity).

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: advisory: APSB26-98

References