← Back

CVE-2026-34625

nvd nist
Published: Apr 14, 2026Modified: Jul 24, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: psirt@adobe.com (Secondary)

Description

Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage.

Affected (2)

2 products
Experience Manager
Experience Manager Screens
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Up to 6.5.24.0
Before 6.5.11.8

References (1)

Timeline

No history available yet.