CVE-2025-66370: Kivitendo

Medium severity, CVSS 5.0. EPSS: 0.3% chance of exploitation in the next 30 days.

Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice in the ZUGFeRD format, it is possible to read and exfiltrate files from the server's filesystem.

Affected products

  • Kivitendo Kivitendo: before 3.9.2 (fixed in 3.9.2)

Published 2025-11-28. Last modified 2026-06-17.