CVE-2017-9095: Divinglog Diving Log

Medium severity, CVSS 5.5. EPSS: 3.7% chance of exploitation in the next 30 days.

XXE in Diving Log 6.0 allows attackers to remotely view local files through a crafted dive.xml file that is mishandled during a Subsurface import.

Affected products

  • Divinglog Diving Log: before 6.0.9 (fixed in 6.0.9)

Published 2017-09-08. Last modified 2026-06-17.