Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.5.25.0CPE matchmatch criteria | cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:* | ||
< 2026.5.0CPE matchmatch criteria | cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:* | ||
>= 0, <= 2026.04CPE match | cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.