CVE-2025-65482: Opensagres Xdocreport
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitrary code via uploading a crafted .docx file.
Affected products
- Opensagres Xdocreport: from 0.9.2, up to and including 2.0.3
Published 2026-01-20. Last modified 2026-06-17.