CRITICAL
An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitrary code via uploading a crafted .docx file
Published Jan 20, 2026
9.8
CRITICALCVSS 3.1
EPSS 0.56%
Description
Affected products
Remediation
References (8)
Change history (0)
No recorded changes yet.