Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 17 Oct 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Adobe
Adobe connect Apple Apple macos Microsoft Microsoft windows |
|
| CPEs | cpe:2.3:a:adobe:connect:*:*:*:*:*:-:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Adobe
Adobe connect Apple Apple macos Microsoft Microsoft windows |
Wed, 15 Oct 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Oct 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute malicious scripts in a victim's browser. Exploitation of this issue requires user interaction in that a victim must navigate to a crafted web page. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high. Scope is changed. | |
| Title | Adobe Connect | Cross-site Scripting (DOM-based XSS) (CWE-79) | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: adobe
Published:
Updated: 2026-02-26T16:57:53.427Z
Reserved: 2025-06-06T15:42:09.517Z
Link: CVE-2025-49553
Updated: 2025-10-15T20:21:18.788Z
Status : Analyzed
Published: 2025-10-14T22:15:37.860
Modified: 2025-10-17T14:59:03.537
Link: CVE-2025-49553
No data.
OpenCVE Enrichment
Updated: 2025-10-20T13:29:47Z