Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 15 Jan 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 28 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 28 Nov 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kivitendo
Kivitendo kivitendo |
|
| Vendors & Products |
Kivitendo
Kivitendo kivitendo |
Fri, 28 Nov 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice in the ZUGFeRD format, it is possible to read and exfiltrate files from the server's filesystem. | |
| Weaknesses | CWE-611 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-01-15T06:46:24.375Z
Reserved: 2025-11-28T00:00:00.000Z
Link: CVE-2025-66370
Updated: 2025-11-28T15:58:30.238Z
Status : Deferred
Published: 2025-11-28T04:16:01.110
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-66370
No data.
OpenCVE Enrichment
Updated: 2025-11-28T08:51:17Z