VDB

CVE-2025-54254

CVE-2025-54254 PUBLISHED CVSS 8.600000381469727 HIGH

Adobe has released a security update for Adobe Experience Manager Forms on Java Enterprise Edition (JEE). This update addresses critical vulnerabilities that could lead to arbitrary code execution and arbitrary file system read. Adobe is aware that CVE-2025-54253 and CVE-2025-54254 have a publicly available proof-of-concept. Adobe is not aware of these issues being exploited in the wild. Vulnerability: Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) Impact: Arbitrary file system read Severity: Critical CVSS: 8.6 CWE: CWE-611

EPSS 77.19% · 99.5th percentile

Risk Scores

CVSS 3.1
8.600000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
EPSS Score
77.19%
99.5th percentile

Timeline

  • Jan 21, 1970 VulnCheck XDB Entry
  • Aug 5, 2025 CVE Published
  • Aug 6, 2025 EPSS Score
  • Aug 6, 2025 PoC Published
  • Aug 6, 2025 PoC Published
  • Aug 6, 2025 PoC Published
  • Aug 6, 2025 PoC Published
  • Aug 6, 2025 PoC Published
  • Aug 6, 2025 PoC Published
  • Aug 7, 2025 PoC Published
  • Aug 7, 2025 PoC Published
  • Aug 8, 2025 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›