VDB
CVE-2025-54254
CVE-2025-54254
PUBLISHED
CVSS 8.600000381469727 HIGH
Adobe has released a security update for Adobe Experience Manager Forms on Java Enterprise Edition (JEE). This update addresses critical vulnerabilities that could lead to arbitrary code execution and arbitrary file system read. Adobe is aware that CVE-2025-54253 and CVE-2025-54254 have a publicly available proof-of-concept. Adobe is not aware of these issues being exploited in the wild. Vulnerability: Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) Impact: Arbitrary file system read Severity: Critical CVSS: 8.6 CWE: CWE-611
EPSS 77.19% · 99.5th percentile
Risk Scores
CVSS 3.1
8.600000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
EPSS Score
77.19%
99.5th percentile
Timeline
- Jan 21, 1970 VulnCheck XDB Entry
- Aug 5, 2025 CVE Published
- Aug 6, 2025 EPSS Score
- Aug 6, 2025 PoC Published
- Aug 6, 2025 PoC Published
- Aug 6, 2025 PoC Published
- Aug 6, 2025 PoC Published
- Aug 6, 2025 PoC Published
- Aug 6, 2025 PoC Published
- Aug 7, 2025 PoC Published
- Aug 7, 2025 PoC Published
- Aug 8, 2025 PoC Published