Junglewise Threat Intelligence

CVE-2025-64854: Adobe Experience Manager stored cross-site scripting in form fields

CVE-2025-64854 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used content management platform for building digital experiences, is vulnerable to stored cross-site scripting (XSS) attacks in form fields. A low-privileged attacker can inject malicious scripts that execute in other users' browsers when they access the affected form, potentially enabling account compromise, session hijacking, or data theft without requiring the attacker to be an administrator.

Technical details

The vulnerability is a stored (persistent) cross-site scripting flaw in Adobe Experience Manager's form field handling, where user-supplied input is not properly sanitized or encoded before being displayed to other users. An attacker with low-level access can inject arbitrary JavaScript into vulnerable form fields; the malicious script is stored and executed in the browser of any victim who views the affected page. The scope is changed, indicating the attack impacts more than just the attacker's own session. No patch availability information is provided in the advisory.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References