Vulnerabilities
Vulnerable Software
Opensagres:  >> Xdocreport  Security Vulnerabilities
A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport v1.0.0 to v2.1.0 allows attackers to execute arbitrary code via injecting crafted template expressions.
CVSS Score
9.8
EPSS Score
0.001
Published
2026-01-20
An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitrary code via uploading a crafted .docx file.
CVSS Score
9.8
EPSS Score
0.001
Published
2026-01-20


Contact Us

Shodan ® - All rights reserved