CVE-2025-52162

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to contain an XML External Entity (XXE) via the RSSReader endpoint. This vulnerability allows attackers to access sensitive data via providing a crafted XML input.

Published 2025-07-18. Last modified 2026-07-05.