Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-54254


Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the local file system, scope is changed. Exploitation of this issue does not require user interaction.


Published

2025-08-05T17:15:29.460

Last Modified

2025-10-02T19:17:17.147

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.6 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-611

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application adobe experience_manager_forms ≤ 6.5.23.0 Yes

References