PT-2026-48097 · Adobe · Experience Manager

CVE-2026-48300

·

Published

2026-06-09

·

Updated

2026-08-24

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier
Description An issue exists due to insufficient protection of the web page structure and a stored Cross-Site Scripting (XSS) flaw. A low-privileged remote attacker can inject malicious scripts into vulnerable form fields. This allows the execution of arbitrary code or malicious JavaScript within the browser of a user who visits the affected page.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08429
CVE-2026-48300

Affected Products

Experience Manager