CVE-2025-66371 – Peppol-py XXE File Disclosure Vulnerability
CVE ID : CVE-2025-66371
Published : Nov. 28, 2025, 4:16 a.m. | 2 hours, 8 minutes ago
Description : Peppol-py before 1.1.1 allows XXE attacks because of the Saxon configuration. When validating XML-based invoices, the XML parser could read files from the filesystem and expose their content to a remote host.
Severity: 5.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more…