CVE-2016-6934: Adobe Experience Manager Forms

Medium severity, CVSS 6.1. EPSS: 2.6% chance of exploitation in the next 30 days.

Adobe Experience Manager Forms versions 6.2 and earlier, LiveCycle 11.0.1, LiveCycle 10.0.4 have an input validation issue in the PMAdmin module that could be used in cross-site scripting attacks.

Affected products

  • Adobe Experience Manager Forms: up to and including 6.2
  • Adobe Livecycle: version 10.0.4 only; version 11.0.1 only

Published 2016-12-15. Last modified 2026-06-17.