← Back to CVE List
Vulnerability Intelligence Report
Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)

CVE-2025-64538

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by injecting malicious scripts into a web page that are executed in the context of the victim's browser. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high. Exploitation of this issue requires user interaction in that a victim must visit a crafted malicious page.

No Active Exploit Signals
CVSS Base Score
9.3
CRITICAL
Exploitability:2.9
Impact Score:5.8
Temporal Score:9.3
EPSS Probability:0.53%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-79 ↗Cross-site Scripting (DOM-based XSS) (CWE-79)

Affected Products & Versions

Vendor Product Affected Versions
Adobe Adobe Experience Manager 0 <= 6.5.23 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.533%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityAdobe Systems Incorporated · Vendor · USA
Reserved2025-11-05T22:51:33
Published2025-12-10T18:24:05
Patch Date2025-12-09
Last Updated2026-02-26T16:21:05

LINK COPIED TO CLIPBOARD