Loading
Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the local file system, scope is changed. Exploitation of this issue does not require user interaction.
Use CWE-611, Adobe vendor hub and Experience Manager Forms product page to widen CVE-2025-54254 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-54253, CVE-2020-9732 and CVE-2020-9733 for nearby disclosures in the same product family.