Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a specially crafted web page.
Metrics
Affected Vendors & Products
References
History
Wed, 15 Apr 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Adobe experience Manager
Adobe experience Manager Screens |
|
| CPEs | cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:* cpe:2.3:a:adobe:experience_manager_screens:*:*:*:*:-:*:*:* |
|
| Vendors & Products |
Adobe experience Manager
Adobe experience Manager Screens |
Wed, 15 Apr 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Adobe
Adobe adobe Experience Manager |
|
| Vendors & Products |
Adobe
Adobe adobe Experience Manager |
Tue, 14 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Apr 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a specially crafted web page. | |
| Title | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: adobe
Published: 2026-04-14T18:26:00.180Z
Updated: 2026-04-14T18:59:02.939Z
Reserved: 2026-03-30T17:30:36.490Z
Link: CVE-2026-34623
Updated: 2026-04-14T18:58:51.729Z
Status : Analyzed
Published: 2026-04-14T19:16:37.903
Modified: 2026-04-15T19:41:53.107
Link: CVE-2026-34623
No data.