Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.4

Adobe Experience Manager: Malicious scripts injected into form fields

CVE-2026-27255
Summary

Adobe Experience Manager versions 6.5.23 and earlier are vulnerable to a security threat where a malicious script can be injected into form fields. This could allow an attacker to do harm to users who interact with those fields, but only if the attacker already has some limited access to the system. Update your software to a newer version to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
adobe experience_manager <= 6.5.24
adobe experience_manager <= 2026.02.0
adobe experience_manager 6.5
adobe experience_manager 6.5
Original title
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts ...
Original description
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
nvd CVSS3.1 5.4
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
Published: 11 Mar 2026 · Updated: 13 Mar 2026 · First seen: 11 Mar 2026