CVE-2025-25035: Jalios Jplatform

High severity, CVSS 7.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper Neutralization of Input During Web Page Generation Cross-site Scripting vulnerability in Jalios JPlatform 10 allows for Reflected XSS and Stored XSS.This issue affects JPlatform 10: before 10.0.8 (SP8), before 10.0.7 (SP7), before 10.0.6 (SP6) and Jalios Workplace 6.2, Jalios Workplace 6.1, Jalios Workplace 6.0, and Jalios Workplace 5.3 to 5.5

Affected products

  • Jalios Jplatform: before 10.0.8 (fixed in 10.0.8); before 10.0.7 (fixed in 10.0.7); before 10.0.6 (fixed in 10.0.6)

Published 2025-03-21. Last modified 2026-06-17.