THREAT OPS › Threat News › [NVD] CVE-2025-64618 (MEDIUM 5.4) — Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the
[NVD] CVE-2025-64618 (MEDIUM 5.4) — Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the
CVE-2025-64618 CVSS: 5.4 MEDIUM Published: 2026-09-08T20:17:26.557
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is chang
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2025-64618cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-64618