Junglewise Threat Intelligence

CVE-2025-64618: Adobe Experience Manager stored XSS in form fields

CVE-2025-64618 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used content management platform, contains a vulnerability that allows low-privileged users to inject malicious scripts into form fields. When other users interact with these compromised fields, malicious code executes in their browsers, potentially leading to session hijacking, credential theft, or unauthorized actions performed on their behalf.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager's form field handling, allowing low-privileged attackers to inject malicious JavaScript that persists in the application. The vulnerability is triggered when a victim browses to a page containing the malicious form field, causing the injected script to execute in their browser context with the victim's privileges. The scope change indicates the vulnerability may affect other components or functionality beyond the initial vulnerable field. No patch information is currently available in the advisory.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References