Security Advisory: CVE-2025-10492 – Jaspersoft Library Deserialisation Vulnerability

CVE-2025-10492 is a newly disclosed Java deserialisation vulnerability affecting Jaspersoft’s JasperReports library that could allow remote code execution in some deployments. While this issue has been patched in commercial editions, community releases are still pending. Skyve is not affected due to its use of trusted local report templates and the absence of remote deserialisation — but we outline what the vulnerability means, who is at risk, and how we’re responding.

Read More
Ben PetitosecurityComment
Skyve 9.4.1

This release of Skyve includes improvements to security configuration persistence and email notifications, as well as important bug fixes for the responsive renderer and enhancements to the SAIL testing framework.

Read More
releasesBen PetitoComment
Skyve 9.4.0 released

Skyve 9.4.0 includes a number of new features and improvements, such as router merging changes, audit archiving, module query imports, and enhancements to both the desktop and responsive renderers. Additionally, there are numerous performance and security improvements.

Read More
releasesBen PetitoComment
Skyve 9.2.0 released

This release of Skyve adds a new security event logging feature, progress towards a new UI component for displaying grids in the responsive renderer, and several security enhancements.

Backups are now also validated prior to truncation and restore, and the SkyveFactory annotation now supports excluding attributes to reduce strobing test results.

Read More
releasesBen PetitoComment