Junglewise Threat Intelligence

CVE-2025-64866: Adobe Experience Manager stored XSS in form fields

CVE-2025-64866 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, used by enterprises to manage digital content and customer experiences, contains a stored cross-site scripting (XSS) vulnerability in form fields. A low-privileged user can inject malicious scripts that execute in other users' browsers when they access the affected page, potentially enabling account hijacking, credential theft, or unauthorized actions within the application.

Technical details

This is a stored (persistent) XSS vulnerability in Adobe Experience Manager's form field handling that fails to properly sanitize or encode user-supplied input. A low-privileged authenticated user can inject malicious JavaScript into vulnerable form fields; the payload is stored and then executed in the browser of any victim who views the affected content. The vulnerability has a changed scope, meaning impact extends beyond the vulnerable component itself. The attack requires authentication and prior knowledge of vulnerable form fields, but no victim interaction beyond normal browsing.

Affected products

  • Adobe Experience Manager <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References