CVE-2025-54252 Details
Description
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. This could result in bypassing security features within the application. Exploitation of this issue requires user interaction in that a victim must browse to the page containing the vulnerable field.
A stored cross-site scripting vulnerability has been identified in Adobe Experience Manager (AEM) versions 6.5.23.0 and earlier. This vulnerability allows low-privileged attackers to inject malicious scripts into vulnerable form fields, potentially bypassing security features within the application. Exploitation requires user interaction, as a victim must visit the page containing the affected field.
Users are advised to update to Adobe Experience Manager 6.5 LTS SP1 (Granite-61551 Hotfix) or version 6.5.23 (Granite-61551 Hotfix). For those on AEM Cloud Service, updates will be applied automatically. Instructions for downloading the update can be found in the release notes for AEM 6.5 LTS and AEM Cloud Service.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://helpx.adobe.com/security/products/experience-manager/apsb25-90.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| adobe experience manager | <= 6.5.23.0 <= 2025.8.0 6.5 - 6.5 sp1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 12, 2025 | Initial Analysis | [email protected] |
| Sep 9, 2025 | New CVE Received | [email protected] |