CVE-2025-65482: Opensagres Xdocreport

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitrary code via uploading a crafted .docx file.

Affected products

  • Opensagres Xdocreport: from 0.9.2, up to and including 2.0.3

Published 2026-01-20. Last modified 2026-06-17.