Known CVE
Apache Tika - XML External Entity Injection
Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1), and tika-parsers (1.13-1.28.5) contain an XML External Entity injection caused by processing crafted XFA files inside PDFs, letting attackers perform XXE attacks remotely, exploit requires crafted PDF input.
CVE-2025-66516
High2025CVSS 9.8CWE-611
cve2025 · apache · tika · xxe · pdf · lfr
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website