CVE-2025-64584
published 2026-09-08CVE-2025-64584: Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious…
PriorityP429medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.28%
18.0th percentile
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_experience_manager_6.5 | <= 6.5.24 | — |
| adobe | adobe_experience_manager_6.5_lts | <= SP2 | — |
| adobe | adobe_experience_manager_as_a_cloud_service | <= 2026.7.0 | — |
| adobe | experience_manager | < 6.5 | 6.5 |
| adobe | experience_manager | < 6.5.25.0 | 6.5.25.0 |
| adobe | experience_manager | < 2026.8.0 | 2026.8.0 |
| adobe | experience_manager | — | — |
| adobe | experience_manager | — | — |
| adobe | experience_manager | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-08
Published