CVE-2026-27266
published 2026-03-11CVE-2026-27266: Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged…
PriorityP429medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.17%
6.3th percentile
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_experience_manager | <= 6.5.23 | — |
| adobe | experience_manager | < 6.5.24.0 | 6.5.24.0 |
| adobe | experience_manager | < 2026.2.0 | 2026.2.0 |
| adobe | experience_manager | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-64581 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64581 [MEDIUM] CVE-2025-64581 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64581 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64554 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64554 [MEDIUM] CVE-2025-64554 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64554 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64604 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64604 [MEDIUM] CVE-2025-64604 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64604 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2026-27255 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27255 [MEDIUM] CVE-2026-27255 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27255 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ado
Wiz
CVE-2026-27261 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27261 [MEDIUM] CVE-2026-27261 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27261 :
Adobe Experience Manager vulnerability analysis and mitigation
Rejected reason: This CVE ID was issued in error by its CVE Numbering Authority.
Source : NVD
Published March 11, 2026
CNA Score N/A
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:experience_manager
Sources
Linux Severity MEDIUM Has Fix Added at: Mar 12, 2026
Windows Severity MEDIUM Has Fix Added at: Mar 12, 2026
Linux Severity MEDIUM Has Fix Added at: Mar 13, 2026
Windows Severity MEDIUM Has Fix Added at: Mar 13, 2026
## Get a CVE risk assessment
Get a prioritize
Wiz
CVE-2025-64547 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64547 [MEDIUM] CVE-2025-64547 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64547 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64794 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64794 [MEDIUM] CVE-2025-64794 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64794 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64797 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64797 [MEDIUM] CVE-2025-64797 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64797 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64823 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64823 [MEDIUM] CVE-2025-64823 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64823 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64551 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64551 [MEDIUM] CVE-2025-64551 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64551 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute malicious scripts in the context of the victim's browser. Exploitation of this issue requires user interaction, such as visiting a crafted URL or interacting with a manipulated web page.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected package
Wiz
CVE-2025-64616 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64616 [MEDIUM] CVE-2025-64616 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64616 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64565 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64565 [MEDIUM] CVE-2025-64565 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64565 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute malicious scripts in the context of the victim's browser. Exploitation of this issue requires user interaction, such as visiting a crafted URL or interacting with a manipulated web page.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected package
Wiz
CVE-2025-64622 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64622 [MEDIUM] CVE-2025-64622 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64622 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64827 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64827 [MEDIUM] CVE-2025-64827 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64827 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64799 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64799 [MEDIUM] CVE-2025-64799 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64799 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2026-27256 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27256 [MEDIUM] CVE-2026-27256 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27256 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ado
Wiz
CVE-2025-64597 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64597 [MEDIUM] CVE-2025-64597 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64597 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64590 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64590 [MEDIUM] CVE-2025-64590 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64590 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64538 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.3
CVE-2025-64538 [CRITICAL] CVE-2025-64538 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64538 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by injecting malicious scripts into a web page that are executed in the context of the victim's browser. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high. Exploitation of this issue requires user interaction in that a victim must visit a crafted malicious page.
Source : NVD
## 9.3
Score
Published December 10, 2025
Severity CRITICAL
CNA Score 9.3
Affected Technologies
Adobe Experience Manager
Has Public Exploit N
Wiz
CVE-2026-27229 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27229 [MEDIUM] CVE-2026-27229 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27229 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:experience_
Wiz
CVE-2025-64873 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64873 [MEDIUM] CVE-2025-64873 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64873 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2026-27263 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27263 [MEDIUM] CVE-2026-27263 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27263 :
Adobe Experience Manager vulnerability analysis and mitigation
Rejected reason: This CVE ID was issued in error by its CVE Numbering Authority.
Source : NVD
Published March 11, 2026
CNA Score N/A
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:experience_manager
Sources
Linux Severity MEDIUM Has Fix Added at: Mar 12, 2026
Windows Severity MEDIUM Has Fix Added at: Mar 12, 2026
Linux Severity MEDIUM Has Fix Added at: Mar 13, 2026
Windows Severity MEDIUM Has Fix Added at: Mar 13, 2026
## Get a CVE risk assessment
Get a prioritize
Wiz
CVE-2026-27236 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27236 [MEDIUM] CVE-2026-27236 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27236 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ado
Wiz
CVE-2025-64804 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64804 [MEDIUM] CVE-2025-64804 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64804 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2026-27265 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27265 [MEDIUM] CVE-2026-27265 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27265 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ado
Wiz
CVE-2025-64541 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64541 [MEDIUM] CVE-2025-64541 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64541 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64560 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64560 [MEDIUM] CVE-2025-64560 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64560 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute malicious scripts in the context of the victim's browser. Exploitation of this issue requires user interaction, such as visiting a crafted URL or interacting with a manipulated web page.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected package
Wiz
CVE-2026-27254 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27254 [MEDIUM] CVE-2026-27254 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27254 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ado
Wiz
CVE-2025-64839 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64839 [MEDIUM] CVE-2025-64839 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64839 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2026-27248 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27248 [MEDIUM] CVE-2026-27248 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27248 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ado
Wiz
CVE-2025-64833 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64833 [MEDIUM] CVE-2025-64833 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64833 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64853 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64853 [MEDIUM] CVE-2025-64853 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64853 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64558 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64558 [MEDIUM] CVE-2025-64558 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64558 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64574 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64574 [MEDIUM] CVE-2025-64574 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64574 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64591 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64591 [MEDIUM] CVE-2025-64591 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64591 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2026-27264 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27264 [MEDIUM] CVE-2026-27264 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27264 :
Adobe Experience Manager vulnerability analysis and mitigation
Rejected reason: This CVE ID was issued in error by its CVE Numbering Authority.
Source : NVD
Published March 11, 2026
CNA Score N/A
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:experience_manager
Sources
Linux Severity MEDIUM Has Fix Added at: Mar 12, 2026
Windows Severity MEDIUM Has Fix Added at: Mar 12, 2026
Linux Severity MEDIUM Has Fix Added at: Mar 13, 2026
Windows Severity MEDIUM Has Fix Added at: Mar 13, 2026
## Get a CVE risk assessment
Get a prioritize
Wiz
CVE-2026-27224 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27224 [MEDIUM] CVE-2026-27224 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27224 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:experience_
Wiz
CVE-2025-64615 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64615 [MEDIUM] CVE-2025-64615 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64615 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64592 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64592 [MEDIUM] CVE-2025-64592 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64592 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64817 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64817 [MEDIUM] CVE-2025-64817 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64817 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64575 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64575 [MEDIUM] CVE-2025-64575 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64575 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64569 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64569 [MEDIUM] CVE-2025-64569 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64569 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute malicious scripts in the context of the victim's browser. Exploitation of this issue requires user interaction, such as visiting a crafted URL or interacting with a manipulated web page.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected package
Wiz
CVE-2025-64872 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.8
CVE-2025-64872 [MEDIUM] CVE-2025-64872 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64872 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 4.8
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 4.8
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 25.4
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
cpe:2.3:
Wiz
CVE-2025-64800 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64800 [MEDIUM] CVE-2025-64800 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64800 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64598 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64598 [MEDIUM] CVE-2025-64598 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64598 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2026-27225 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27225 [MEDIUM] CVE-2026-27225 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27225 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ado
Wiz
CVE-2025-64614 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64614 [MEDIUM] CVE-2025-64614 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64614 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64790 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64790 [MEDIUM] CVE-2025-64790 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64790 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2026-27226 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27226 [MEDIUM] CVE-2026-27226 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27226 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:experience_
Wiz
CVE-2026-27233 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27233 [MEDIUM] CVE-2026-27233 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27233 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ado
Wiz
CVE-2025-64861 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64861 [MEDIUM] CVE-2025-64861 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64861 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64847 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64847 [MEDIUM] CVE-2025-64847 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64847 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64572 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64572 [MEDIUM] CVE-2025-64572 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64572 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64566 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64566 [MEDIUM] CVE-2025-64566 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64566 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute malicious scripts in the context of the victim's browser. Exploitation of this issue requires user interaction, such as visiting a crafted URL or interacting with a manipulated web page.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected package
Wiz
CVE-2026-27234 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27234 [MEDIUM] CVE-2026-27234 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27234 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:experience_
Wiz
CVE-2025-64821 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64821 [MEDIUM] CVE-2025-64821 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64821 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2026-27266 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27266 [MEDIUM] CVE-2026-27266 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27266 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ado
Wiz
CVE-2025-64814 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64814 [MEDIUM] CVE-2025-64814 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64814 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64594 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64594 [MEDIUM] CVE-2025-64594 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64594 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64559 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64559 [MEDIUM] CVE-2025-64559 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64559 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64792 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64792 [MEDIUM] CVE-2025-64792 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64792 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2026-27251 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27251 [MEDIUM] CVE-2026-27251 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27251 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ado
Wiz
CVE-2025-64550 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64550 [MEDIUM] CVE-2025-64550 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64550 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute malicious scripts in the context of the victim's browser. Exploitation of this issue requires user interaction, such as visiting a crafted URL or interacting with a manipulated web page.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected package
Wiz
CVE-2026-27250 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27250 [MEDIUM] CVE-2026-27250 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27250 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ado
Wiz
CVE-2025-64553 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64553 [MEDIUM] CVE-2025-64553 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64553 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64845 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64845 [MEDIUM] CVE-2025-64845 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64845 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64852 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64852 [MEDIUM] CVE-2025-64852 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64852 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64612 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64612 [MEDIUM] CVE-2025-64612 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64612 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2026-27242 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27242 [MEDIUM] CVE-2026-27242 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27242 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ado
Wiz
CVE-2025-64857 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64857 [MEDIUM] CVE-2025-64857 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64857 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2026-27230 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27230 [MEDIUM] CVE-2026-27230 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27230 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ado
Wiz
CVE-2025-64619 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64619 [MEDIUM] CVE-2025-64619 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64619 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64578 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64578 [MEDIUM] CVE-2025-64578 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64578 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64620 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64620 [MEDIUM] CVE-2025-64620 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64620 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64555 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64555 [MEDIUM] CVE-2025-64555 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64555 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2026-27232 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27232 [MEDIUM] CVE-2026-27232 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27232 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ado
Wiz
CVE-2025-64881 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64881 [MEDIUM] CVE-2025-64881 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64881 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64789 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64789 [MEDIUM] CVE-2025-64789 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64789 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64585 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64585 [MEDIUM] CVE-2025-64585 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64585 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2026-27239 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27239 [MEDIUM] CVE-2026-27239 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27239 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:experience_
Wiz
CVE-2025-64611 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64611 [MEDIUM] CVE-2025-64611 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64611 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64539 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.3
CVE-2025-64539 [CRITICAL] CVE-2025-64539 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64539 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by injecting malicious scripts into a web page that are executed in the context of the victim's browser. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high. Exploitation of this issue requires user interaction in that a victim must visit a crafted malicious page.
Source : NVD
## 9.3
Score
Published December 10, 2025
Severity CRITICAL
CNA Score 9.3
Affected Technologies
Adobe Experience Manager
Has Public Exploit N
Wiz
CVE-2025-64863 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64863 [MEDIUM] CVE-2025-64863 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64863 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64602 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64602 [MEDIUM] CVE-2025-64602 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64602 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64544 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64544 [MEDIUM] CVE-2025-64544 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64544 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute malicious scripts in the context of the victim's browser. Exploitation of this issue requires user interaction, such as visiting a crafted URL or interacting with a manipulated web page.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected package
Wiz
CVE-2025-64599 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64599 [MEDIUM] CVE-2025-64599 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64599 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2026-27231 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27231 [MEDIUM] CVE-2026-27231 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27231 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:experience_
Wiz
CVE-2026-27235 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27235 [MEDIUM] CVE-2026-27235 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27235 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ado
Wiz
CVE-2025-64537 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.3
CVE-2025-64537 [CRITICAL] CVE-2025-64537 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64537 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by injecting malicious scripts into a web page that are executed in the context of the victim's browser. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high. Exploitation of this issue requires user interaction in that a victim must visit a crafted malicious page.
Source : NVD
## 9.3
Score
Published December 10, 2025
Severity CRITICAL
CNA Score 9.3
Affected Technologies
Adobe Experience Manager
Has Public Exploit N
Wiz
CVE-2025-64546 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64546 [MEDIUM] CVE-2025-64546 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64546 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64576 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64576 [MEDIUM] CVE-2025-64576 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64576 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2026-27252 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27252 [MEDIUM] CVE-2026-27252 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27252 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ado
Wiz
CVE-2025-64545 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64545 [MEDIUM] CVE-2025-64545 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64545 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute malicious scripts in the context of the victim's browser. Exploitation of this issue requires user interaction, such as visiting a crafted URL or interacting with a manipulated web page.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected package
Wiz
CVE-2025-64796 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64796 [MEDIUM] CVE-2025-64796 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64796 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64820 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64820 [MEDIUM] CVE-2025-64820 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64820 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64841 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64841 [MEDIUM] CVE-2025-64841 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64841 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64791 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64791 [MEDIUM] CVE-2025-64791 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64791 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64829 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64829 [MEDIUM] CVE-2025-64829 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64829 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64623 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64623 [MEDIUM] CVE-2025-64623 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64623 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2026-27257 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27257 [MEDIUM] CVE-2026-27257 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27257 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ado
Wiz
CVE-2026-27244 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27244 [MEDIUM] CVE-2026-27244 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27244 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ado
Wiz
CVE-2025-64627 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64627 [MEDIUM] CVE-2025-64627 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64627 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64582 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64582 [MEDIUM] CVE-2025-64582 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64582 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2026-27223 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27223 [MEDIUM] CVE-2026-27223 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27223 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:experience_
Wiz
CVE-2026-27259 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27259 [MEDIUM] CVE-2026-27259 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27259 :
Adobe Experience Manager vulnerability analysis and mitigation
Rejected reason: This CVE ID was issued in error by its CVE Numbering Authority.
Source : NVD
Published March 11, 2026
CNA Score N/A
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:experience_manager
Sources
Linux Severity MEDIUM Has Fix Added at: Mar 12, 2026
Windows Severity MEDIUM Has Fix Added at: Mar 12, 2026
Linux Severity MEDIUM Has Fix Added at: Mar 13, 2026
Windows Severity MEDIUM Has Fix Added at: Mar 13, 2026
## Get a CVE risk assessment
Get a prioritize
Wiz
CVE-2025-64802 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64802 [MEDIUM] CVE-2025-64802 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64802 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64875 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64875 [MEDIUM] CVE-2025-64875 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64875 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64564 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64564 [MEDIUM] CVE-2025-64564 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64564 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute malicious scripts in the context of the victim's browser. Exploitation of this issue requires user interaction, such as visiting a crafted URL or interacting with a manipulated web page.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected package
Wiz
CVE-2025-64793 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64793 [MEDIUM] CVE-2025-64793 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64793 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64603 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64603 [MEDIUM] CVE-2025-64603 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64603 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64556 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64556 [MEDIUM] CVE-2025-64556 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64556 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64606 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64606 [MEDIUM] CVE-2025-64606 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64606 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64548 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64548 [MEDIUM] CVE-2025-64548 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64548 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2026-27241 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27241 [MEDIUM] CVE-2026-27241 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27241 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ado
Wiz
CVE-2026-27247 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27247 [MEDIUM] CVE-2026-27247 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27247 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ado
Wiz
CVE-2025-64858 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64858 [MEDIUM] CVE-2025-64858 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64858 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64605 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64605 [MEDIUM] CVE-2025-64605 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64605 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64609 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64609 [MEDIUM] CVE-2025-64609 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64609 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2026-27240 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27240 [MEDIUM] CVE-2026-27240 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27240 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ado
Wiz
CVE-2025-64562 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64562 [MEDIUM] CVE-2025-64562 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64562 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute malicious scripts in the context of the victim's browser. Exploitation of this issue requires user interaction, such as visiting a crafted URL or interacting with a manipulated web page.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected package
Wiz
CVE-2025-64563 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64563 [MEDIUM] CVE-2025-64563 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64563 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute malicious scripts in the context of the victim's browser. Exploitation of this issue requires user interaction, such as visiting a crafted URL or interacting with a manipulated web page.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected package
Wiz
CVE-2025-64808 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64808 [MEDIUM] CVE-2025-64808 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64808 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2026-27228 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27228 [MEDIUM] CVE-2026-27228 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27228 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ado
Wiz
CVE-2025-64869 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64869 [MEDIUM] CVE-2025-64869 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64869 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64887 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64887 [MEDIUM] CVE-2025-64887 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64887 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute malicious scripts in the context of the victim's browser. Exploitation of this issue requires user interaction, such as visiting a crafted URL or interacting with a manipulated web page.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected package
Wiz
CVE-2025-64596 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64596 [MEDIUM] CVE-2025-64596 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64596 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64580 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64580 [MEDIUM] CVE-2025-64580 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64580 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64822 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64822 [MEDIUM] CVE-2025-64822 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64822 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64586 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64586 [MEDIUM] CVE-2025-64586 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64586 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64826 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64826 [MEDIUM] CVE-2025-64826 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64826 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2026-27249 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27249 [MEDIUM] CVE-2026-27249 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27249 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ado
Wiz
CVE-2025-64607 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64607 [MEDIUM] CVE-2025-64607 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64607 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64825 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64825 [MEDIUM] CVE-2025-64825 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64825 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64543 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64543 [MEDIUM] CVE-2025-64543 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64543 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute malicious scripts in the context of the victim's browser. Exploitation of this issue requires user interaction, such as visiting a crafted URL or interacting with a manipulated web page.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected package
Wiz
CVE-2025-64557 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64557 [MEDIUM] CVE-2025-64557 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64557 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2026-27262 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27262 [MEDIUM] CVE-2026-27262 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27262 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:experience_
Wiz
CVE-2025-64803 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64803 [MEDIUM] CVE-2025-64803 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64803 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64577 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64577 [MEDIUM] CVE-2025-64577 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64577 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64601 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64601 [MEDIUM] CVE-2025-64601 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64601 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64801 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64801 [MEDIUM] CVE-2025-64801 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64801 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64600 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64600 [MEDIUM] CVE-2025-64600 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64600 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64583 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64583 [MEDIUM] CVE-2025-64583 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64583 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute malicious scripts in the context of the victim's browser. Exploitation of this issue requires user interaction, such as visiting a crafted URL or interacting with a manipulated web page.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected package
Wiz
CVE-2025-64613 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64613 [MEDIUM] CVE-2025-64613 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64613 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64840 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64840 [MEDIUM] CVE-2025-64840 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64840 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64888 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64888 [MEDIUM] CVE-2025-64888 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64888 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute malicious scripts in the context of the victim's browser. Exploitation of this issue requires user interaction, such as visiting a crafted URL or interacting with a manipulated web page.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected package
Wiz
CVE-2025-64626 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64626 [MEDIUM] CVE-2025-64626 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64626 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2026-27237 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27237 [MEDIUM] CVE-2026-27237 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27237 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ado
Wiz
CVE-2025-64579 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64579 [MEDIUM] CVE-2025-64579 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64579 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64549 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64549 [MEDIUM] CVE-2025-64549 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64549 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2025-64850 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64850 [MEDIUM] CVE-2025-64850 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64850 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2026-27253 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27253 [MEDIUM] CVE-2026-27253 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27253 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:ado
Wiz
CVE-2025-64593 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-64593 [MEDIUM] CVE-2025-64593 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-64593 :
Adobe Experience Manager vulnerability analysis and mitigation
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published December 10, 2025
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a
Wiz
CVE-2026-27260 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27260 [MEDIUM] CVE-2026-27260 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27260 :
Adobe Experience Manager vulnerability analysis and mitigation
Rejected reason: This CVE ID was issued in error by its CVE Numbering Authority.
Source : NVD
Published March 11, 2026
CNA Score N/A
Affected Technologies
Adobe Experience Manager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:experience_manager
Sources
Linux Severity MEDIUM Has Fix Added at: Mar 12, 2026
Windows Severity MEDIUM Has Fix Added at: Mar 12, 2026
Linux Severity MEDIUM Has Fix Added at: Mar 13, 2026
Windows Severity MEDIUM Has Fix Added at: Mar 13, 2026
## Get a CVE risk assessment
Get a prioritize
2026-03-11
Published