VDB
GCVE-110-NCSC-2026-90
GCVE-110-NCSC-2026-90
Advisory PublishedCVSS 5.4/10
Adobe Experience Manager versions 6.5.23 and earlier contain a stored Cross-Site Scripting (XSS) vulnerability that enables attackers to inject malicious scripts into form fields, potentially executing harmful JavaScript in users' browsers.
Weaknesses (CWE)
CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Adobe | vers:unknown/* | — | — |
Aliases
CVE-2026-27223CVE-2026-27224CVE-2026-27225CVE-2026-27227CVE-2026-27228CVE-2026-27229CVE-2026-27230CVE-2026-27231CVE-2026-27232CVE-2026-27233CVE-2026-27234CVE-2026-27235CVE-2026-27236CVE-2026-27237CVE-2026-27239CVE-2026-27240CVE-2026-27241CVE-2026-27242CVE-2026-27244CVE-2026-27247CVE-2026-27248CVE-2026-27249CVE-2026-27250CVE-2026-27251CVE-2026-27252CVE-2026-27253CVE-2026-27254CVE-2026-27255CVE-2026-27256CVE-2026-27257CVE-2026-27262CVE-2026-27265CVE-2026-27266
References
Browse GCVE Records
74,267 records in the GCVE database · Updated July 22, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.