CVE-2025-54254

HIGH EXPLOITED

Adobe Experience Manager Forms < 6.5.23.0 - XXE

Title source: rule

Description

Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the local file system, scope is changed. Exploitation of this issue does not require user interaction.

Exploits (1)

vulncheck_xdb SCANNER
remote
https://github.com/zoomdbz/AEMPWN

Scores

CVSS v3 8.6
EPSS 0.0025
EPSS Percentile 48.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Details

VulnCheck KEV 2025-08-12
CWE
CWE-611
Status published
Products (1)
adobe/experience_manager_forms < 6.5.23.0
Published Aug 05, 2025
Tracked Since Feb 18, 2026