Skip to content

Known CVE

Apache Tika - XML External Entity Injection

Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1), and tika-parsers (1.13-1.28.5) contain an XML External Entity injection caused by processing crafted XFA files inside PDFs, letting attackers perform XXE attacks remotely, exploit requires crafted PDF input.

CVE-2025-66516

High2025CVSS 9.8CWE-611

cve2025 · apache · tika · xxe · pdf · lfr

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website