CVE-2025-66370
CVE-2025-66370
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
28 Nov 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice in the ZUGFeRD format, it is possible to read and exfiltrate files from the server's filesystem.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Affected products
kivitendo · kivitendoWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://blog.kivitendo.de/?p=1415https://github.com/kivitendo/kivitendo-erp/blob/fd3f993fc731cbcaa5eb87d55df7c82df4df9c09/doc/changeloghttps://github.com/kivitendo/kivitendo-erp/commit/1286dee72f9919166178d0cdb5f52f13b0f7d4dehttps://github.com/kivitendo/kivitendo-erp/commit/f6ba56bd8d22a428534057589baace6b7bfdf2e9https://invoice.secvuln.info