Opensagres maintains XDocReport, a document-generation library that processes templates and XML-based formats, with a vulnerability profile centered on template-injection and XML external-entity weaknesses that reflect the parsing and templating demands of the codebase. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opensagres over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-65482CRITICAL An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitrary code via uploading a crafted .docx file. | Jan 20, 2026 | 9.8 | 31 | NO | NO |
CVE-2025-64087CRITICAL A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport v1.0.0 to v2.1.0 allows attackers to execute arbitrary code via injecting | Jan 20, 2026 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opensagres.
Media articles that mention a CVE ID that affects a product developed by Opensagres — matched by CVE ID, not by vendor name.