Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
                
            Metrics
Affected Vendors & Products
References
        History
                    Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        
        epss
         
  | 
    
        
        
        epss
         
  | 
Fri, 13 Jun 2025 13:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Adobe
         Adobe experience Manager  | 
|
| CPEs | cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:* cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*  | 
|
| Vendors & Products | 
        
        Adobe
         Adobe experience Manager  | 
Wed, 11 Jun 2025 16:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Tue, 10 Jun 2025 22:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. | |
| Title | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) | |
| Weaknesses | CWE-79 | |
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: adobe
Published: 2025-06-10T22:19:45.901Z
Updated: 2025-06-11T15:32:46.174Z
Reserved: 2025-04-30T20:47:54.953Z
Link: CVE-2025-46887
Updated: 2025-06-11T15:32:41.576Z
Status : Analyzed
Published: 2025-06-10T23:15:30.763
Modified: 2025-06-13T13:01:45.833
Link: CVE-2025-46887
No data.