Back to Database
Status published
Medium
CVE-2025-66370
Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic...
Vulnerability Description
Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice in the ZUGFeRD format, it is possible to read and exfiltrate files from the server's filesystem.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-66370
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/kivitendo/kivitendo-erp/blob/fd3f993fc731cbcaa5eb87d55df7c82df4df9c09/doc/changelog
- https://github.com/kivitendo/kivitendo-erp/commit/1286dee72f9919166178d0cdb5f52f13b0f7d4de
- https://github.com/kivitendo/kivitendo-erp/commit/f6ba56bd8d22a428534057589baace6b7bfdf2e9
- https://blog.kivitendo.de/?p=1415
- https://invoice.secvuln.info
Affected Vendor
kivitendo
View all reports →Affected Software
kivitendo
Vulnerable Versions:
0
Timeline
Official Publish:
November 28th, 2025
Last Modified:
January 15th, 2026
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N