Adobe – CVE-2025-47110 and Massive AEM Exposure: 225 vulnerabilities
Adobe released critical security updates in June for multiple products:
- 
225 vulnerabilities in Adobe Experience Manager (AEM) 
- 
CVE-2025-47110 in Adobe Commerce (Magento) – a high-risk reflected XSS vulnerability (CVSS 9.1) that can lead to client-side code execution. 
Risks:
- 
XSS can allow attackers to hijack sessions, modify content, or launch phishing attacks 
- 
In unpatched Magento stores, attackers can exploit poor sanitization in URL parameters to inject malicious scripts. 
Recommendations:
- 
Update AEM and Commerce to latest versions immediately 
- 
Use a Web Application Firewall (WAF) to block known exploit vectors 
- 
Perform regular scans and code reviews for custom plugins or templates. 
