CVE-2025-54254
HIGH EXPLOITEDAdobe Experience Manager Forms < 6.5.23.0 - XXE
Title source: ruleDescription
Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the local file system, scope is changed. Exploitation of this issue does not require user interaction.
Exploits (1)
Scores
CVSS v3
8.6
EPSS
0.0025
EPSS Percentile
48.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Details
VulnCheck KEV
2025-08-12
CWE
CWE-611
Status
published
Products (1)
adobe/experience_manager_forms
< 6.5.23.0
Published
Aug 05, 2025
Tracked Since
Feb 18, 2026