Xdocreport
Opensagres · 2 CVEs
CVE-2025-65482
CRITICAL
An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitr…
Jan 20, 2026
CVE-2025-64087
CRITICAL
A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport v1.0.0 to v2…
Jan 20, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-65482 | An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitrary code via uploading a crafted .docx f… | CRITICAL | 0.56% | Jan 20, 2026 |
| CVE-2025-64087 | A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport v1.0.0 to v2.1.0 allows attackers to execute arbitra… | CRITICAL | 0.57% | Jan 20, 2026 |
Showing 1 to 2 of 2 CVEs