CVE-2025-35113: Atlassian Agiloft
High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.
Agiloft Release 28 does not properly neutralize special elements used in an EUI template engine, allowing an authenticated attacker to achieve remote code execution by loading a specially crafted payload. Users should upgrade to Agiloft Release 31.
Affected products
- Atlassian Agiloft: from 19, before 31 (fixed in 31)
Published 2025-08-26. Last modified 2026-06-17.