Skip to content

Known CVE

Apache Tika - XXE Injection

Apache Tika versions 1.13 through 3.2.1 are vulnerable to XXE via malicious XFA in PDFs, allowing file read and SSRF attacks.

CVE-2025-54988

Critical2025CVSS 9.8CWE-611

cve2025 · apache · tika · xxe · ssrf · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website