← back
CVE-2025-66370

CVE-2025-66370

CVSS 5 MEDIUMEPSS 0.3%CWE-611
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
28 Nov 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice in the ZUGFeRD format, it is possible to read and exfiltrate files from the server's filesystem.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Affected products
kivitendo · kivitendo

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →