The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Sites component. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:HAdobe Experience Manager
APPAdobe≤ 6.2.1.206.3.0.0 – 6.3.3.86.4.0.0 – 6.4.8.16.5.0.0 – 6.5.5.0Adobe Experience Manager Forms
APPAdobe6.4.8.16.5.5.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
Related vulnerabilities
CVE-2025-54253CRITICAL10.0⚠ KEVPL ✓same product
RCE przez błędną konfigurację w Adobe Experience Manager Forms
CVE-2026-48259CRITICAL9.6PL ✓same product
Adobe Experience Manager — SSRF umożliwiający zdalne wykonanie kodu
CVE-2026-48359CRITICAL9.6PL ✓same product
Adobe Experience Manager — XXE umożliwiające RCE i odczyt plików
CVE-2026-34691CRITICAL9.3PL ✓same product
Stored XSS w Adobe Experience Manager Forms JEE – krytyczna podatność
CVE-2025-64537CRITICAL9.3PL ✓same product
DOM-based XSS w Adobe Experience Manager umożliwiający RCE