CVE-2026-48355
published 2026-07-14CVE-2026-48355: Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious…
PriorityP429medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.17%
6.3th percentile
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_experience_manager_6.5 | <= 6.5.25 | — |
| adobe | adobe_experience_manager_6.5_lts | <= SP2 | — |
| adobe | adobe_experience_manager_as_a_cloud_service | <= 2026.5.0 | — |
| adobe | experience_manager | <= 6.5.25.0 | — |
| adobe | experience_manager | <= 2020.5.0 | — |
| adobe | experience_manager | — | — |
| adobe | experience_manager | — | — |
| adobe | experience_manager | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Adobe Experience Manager Form Field cross site scripting (Nessus ID 327021)
vuldb·2026-07-20·CVSS 5.4
CVE-2026-48355 [MEDIUM] Adobe Experience Manager Form Field cross site scripting (Nessus ID 327021)
A vulnerability marked as problematic has been reported in Adobe Experience Manager. This affects an unknown function of the component Form Field. This manipulation causes cross site scripting.
This vulnerability is handled as CVE-2026-48355. The attack can be initiated remotely. There is not any exploit available.
GHSA
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields.
ghsa_unreviewed·2026-07-14
CVE-2026-48355 [MEDIUM] CWE-79 Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields.
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-14
Published