5.4mediumMedium
CVE-2026-48280
Adobe Experience Manager
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Exploitation status
- A vendor advisory or patch reference has been published.
What the metrics mean
- It is reachable over a network, without needing local access.
- For an attacker who can reach it, no special conditions are needed to exploit it.
- To exploit it, an ordinary user account is needed.
- Beyond that, someone has to be persuaded to take an action first.
Scoring
- CVSS
- 5.4 (v3.1)
- Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N- Weakness
- CWE-79
- Assigned by
- psirt@adobe.com
Dates
- Published
- 2026-06-09
- Last modified
- 2026-08-28
- Sources
- NVD
Affected products
- Adobe Experience Manager- 6.5.25.0, - 2026.5.0, 6.5
As listed in the NVD configuration data. Not a statement about your estate.