← Back

CVE-2026-48266

nvd nist
Published: Jun 9, 2026Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: psirt@adobe.com (Secondary)

Description

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

Affected (4)

1 product
Experience Manager
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Before 6.5.25.0
Before 2026.5.0
Version 6.5
Version 6.5 sp1

References (1)

Timeline

No history available yet.