CVE-2025-66370

MEDIUM

Kivitendo <3.9.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice in the ZUGFeRD format, it is possible to read and exfiltrate files from the server's filesystem.

Scores

CVSS v3 5.0
EPSS 0.0003
EPSS Percentile 9.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-611
Status published
Products (1)
kivitendo/kivitendo < 3.9.2
Published Nov 28, 2025
Tracked Since Feb 18, 2026