5.4mediumMedium

CVE-2026-34625

Adobe Experience Manager

Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage.

Exploitation status

  • A vendor advisory or patch reference has been published.

What the metrics mean

  • It is reachable over a network, without needing local access.
  • For an attacker who can reach it, no special conditions are needed to exploit it.
  • To exploit it, an ordinary user account is needed.
  • Beyond that, someone has to be persuaded to take an action first.

Scoring

CVSS
5.4 (v3.1)
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness
CWE-79
Assigned by
psirt@adobe.com

Dates

Published
2026-04-14
Last modified
2026-08-28
Sources
NVD

Affected products

  • Adobe Experience Manager- 6.5.24.0
  • Adobe Experience Manager Screens- 6.5.11.8

As listed in the NVD configuration data. Not a statement about your estate.

References