CVE-2025-54859: Neojapan Inc Desknet's Neo
Medium severity, CVSS 4.6. EPSS: 0.3% chance of exploitation in the next 30 days.
Stored cross-site scripting (XSS) vulnerability in desknet's NEO V9.0R2.0 and earlier allow execution of arbitrary JavaScript in a user’s web browser.
Affected products
- Neojapan Inc Desknet's Neo: up to and including V9.0R2.0
Published 2025-10-16. Last modified 2026-10-09.