CVE-2025-58070: Implem Inc Pleasanter

Medium severity, CVSS 5.1. EPSS: 0.2% chance of exploitation in the next 30 days.

Pleasanter contains a stored cross-site scripting vulnerability in Preview for Attachments, which allows an attacker to execute an arbitrary script in a logged-in user's web browser.

Affected products

  • Implem Inc Pleasanter: up to and including 1.4.20.0

Published 2025-10-24. Last modified 2026-10-08.