Opensagres

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 3
    Known Exploited: 0
    3
    Critical Level Threats
    0
    High Level Threats
    0
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-38165

    Server‑Side Template Injection in xdocreport Velocity Engine Allows Arbitrary Code Execution

    Last Modified: Aug 18, 2026
    Published: Aug 17, 2026

    CVE-2025-64087

    A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport v1.0.0 to v2.1.0 allows attackers to execute arbitrary code via injecting crafted template expressions.

    Last Modified: Feb 03, 2026
    Published: Jan 20, 2026

    CVE-2025-65482

    An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitrary code via uploading a crafted .docx file.

    Last Modified: Feb 03, 2026
    Published: Jan 20, 2026
    Items Per Page