Known CVE
Apache Tika - XXE Injection
Apache Tika versions 1.13 through 3.2.1 are vulnerable to XXE via malicious XFA in PDFs, allowing file read and SSRF attacks.
CVE-2025-54988
Critical2025CVSS 9.8CWE-611
cve2025 · apache · tika · xxe · ssrf · vuln
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website