143 CVEs affecting Xmlsoft products, 0 known to be exploited (CISA KEV), with EPSS scores. Most affected: LIBXML2, Libxslt, Libxml, Xmllint.