CVE-2025-54254 is an Improper Restriction of XML External Entity Reference (XXE) vulnerability affecting Adobe Experience Manager versions 6.5.23 and earlier, specifically impacting AEM Forms. This high-severity vulnerability (CVSS 8.6) allows an unauthenticated attacker to remotely read arbitrary files from the file system without user interaction. While no public exploit code is listed for Metasploit, Nuclei, or ExploitDB, media coverage and community discussion indicate active exploitation and public Proof-of-Concepts, with CISA reporting it is being exploited in attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.5.23.0CPE matchmatch criteria | cpe:2.3:a:adobe:experience_manager_forms:*:*:*:*:*:*:*:* | ||
>= 0, <= 6.5.23CPE match | cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.