CVE-2025-25363: Thepluginpeople Enterprise Mail Handler
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
An authenticated stored cross-site scripting (XSS) vulnerability in The Plugin People Enterprise Mail Handler for Jira Data Center (JEMH) before v4.1.69-dc allows attackers with Administrator privileges to execute arbitrary Javascript in context of a user's browser via injecting a crafted payload into the HTML field of a template.
Affected products
- Thepluginpeople Enterprise Mail Handler: from 4.1.53-dc, before 4.1.69-dc (fixed in 4.1.69-dc)
Published 2025-03-13. Last modified 2026-06-17.