CVE-2025-64537
published 2025-12-10CVE-2025-64537: Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code…
PriorityP348critical9.3CVSS 3.1
AVNACLPRNUIRSCCHIHAN
EPSS
0.74%
52.8th percentile
Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by injecting malicious scripts into a web page that are executed in the context of the victim's browser. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high. Exploitation of this issue requires user interaction in that a victim must visit a crafted malicious page.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_experience_manager | <= 6.5.23 | — |
| adobe | experience_manager | < 6.5.24.0 | 6.5.24.0 |
| adobe | experience_manager | < 2025.12.0 | 2025.12.0 |
| adobe | experience_manager | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Adobe Experience Manager up to 6.5.23 cross site scripting (apsb25-115 / Nessus ID 278346)
vuldb·2026-09-29·CVSS 9.3
CVE-2025-64537 [CRITICAL] Adobe Experience Manager up to 6.5.23 cross site scripting (apsb25-115 / Nessus ID 278346)
A vulnerability categorized as problematic has been discovered in Adobe Experience Manager up to 6.5.23. This impacts an unknown function. Such manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2025-64537. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
GHSA
GHSA-pcg6-f6g2-82xx: Adobe Experience Manager versions 6
ghsa_unreviewed·2025-12-10
CVE-2025-64537 [CRITICAL] CWE-79 GHSA-pcg6-f6g2-82xx: Adobe Experience Manager versions 6
Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by injecting malicious scripts into a web page that are executed in the context of the victim's browser. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high. Exploitation of this issue requires user interaction in that a victim must visit a crafted malicious page.
No detection rules found.
No public exploits indexed.
2025-12-10
Published