CVE-2026-34691Critical· 9.3▾ MidnightAdobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Mali…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 51.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 29.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
0.2% → 0.4%
Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.
experience_manager <= 6.5.24.0experience_manager = 6.5Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-34693High· 8.0Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability
CVE-2025-64542Medium· 5.4Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability
CVE-2025-64588Medium· 5.4Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields
CVE-2026-75670Medium· 5.4Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability
CVE-2026-75693Medium· 5.4Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability
CVE-2026-75714Medium· 5.4Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability