CVE-2025-9719: Zoneland o2oa

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

A weakness has been identified in O2OA up to 10.0-410. This vulnerability affects unknown code of the file /x_processplatform_assemble_designer/jaxrs/script of the component Personal Profile Page. Executing manipulation of the argument name/alias/description/applicationName can lead to cross site scripting. The attack can be executed remotely. The exploit has been made available to the public and could be exploited.

Affected products

  • Zoneland o2oa: up to and including 10.0-410

Published 2025-08-31. Last modified 2026-06-17.