Junglewise Threat Intelligence

CVE-2025-64589: Adobe Experience Manager stored XSS in form fields

CVE-2025-64589 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used digital content management platform, contains a stored cross-site scripting vulnerability in form field handling. A low-privileged attacker can inject malicious scripts that persist in the system and execute in the browsers of users who view affected pages, potentially leading to account compromise, credential theft, or unauthorized actions performed on behalf of legitimate users.

Technical details

This is a stored XSS vulnerability in Adobe Experience Manager's form field processing. The root cause is insufficient input validation or output encoding of user-supplied data in form fields, allowing a low-privileged attacker to inject malicious JavaScript. The vulnerability has a changed scope, indicating it may cross security boundaries. An attacker with valid user credentials can craft malicious input that persists in the application's database; when any user views the affected page or form, the injected script executes in their browser context with their privileges. No patch information is currently available.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References