CVE-2026-48263
published 2026-07-14CVE-2026-48263: Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious…
PriorityP429medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.17%
6.3th percentile
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_experience_manager_6.5 | <= 6.5.25 | — |
| adobe | adobe_experience_manager_6.5_lts | <= SP2 | — |
| adobe | adobe_experience_manager_as_a_cloud_service | <= 2026.5.0 | — |
| adobe | experience_manager | <= 6.5.25.0 | — |
| adobe | experience_manager | <= 2020.5.0 | — |
| adobe | experience_manager | — | — |
| adobe | experience_manager | — | — |
| adobe | experience_manager | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Adobe Experience Manager Form Field cross site scripting (Nessus ID 327021)
vuldb·2026-07-20·CVSS 5.4
CVE-2026-48263 [MEDIUM] Adobe Experience Manager Form Field cross site scripting (Nessus ID 327021)
A vulnerability labeled as problematic has been found in Adobe Experience Manager. The impacted element is an unknown function of the component Form Field. The manipulation of the argument Field results in cross site scripting.
This vulnerability is known as CVE-2026-48263. It is possible to launch the attack remotely. No exploit is available.
GHSA
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields.
ghsa_unreviewed·2026-07-14
CVE-2026-48263 [MEDIUM] CWE-79 Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields.
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-14
Published