Back

MEDIUM

Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)

Published Sep 8, 2026

Description

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner adobe
Published Sep 8, 2026
Updated Sep 9, 2026
Reserved Aug 18, 2026

CISA Vulnrichment

Updated Sep 9, 2026

NVD

Status Analyzed
Modified Sep 11, 2026

Red Hat

No data

ENISA EUVD

Assigner adobe
Published Sep 8, 2026
Updated Sep 9, 2026

GitHub

No data