VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,331)

page 12 of 67
  • CVE-2019-1060HigOct 10, 2019
    risk 0.58cvss 8.8epss 0.14

    A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'.

  • CVE-2019-13990CriJul 26, 2019
    risk 0.58cvss 9.8epss 0.16

    initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.

  • CVE-2019-0790HigApr 9, 2019
    risk 0.58cvss 8.8epss 0.16

    A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0791, CVE-2019-0792, CVE-2019-0793, CVE-2019-0795.

  • CVE-2019-0756HigApr 9, 2019
    risk 0.58cvss 8.8epss 0.13

    A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'.

  • CVE-2017-9362HigMar 25, 2019
    risk 0.58cvss 8.8epss 0.04

    ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.

  • CVE-2018-1000823CriDec 20, 2018
    risk 0.58cvss 10.0epss 0.02

    exist version <= 5.0.0-RC4 contains a XML External Entity (XXE) vulnerability in XML Parser for REST Server that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.

  • CVE-2017-9096HigNov 8, 2017
    risk 0.58cvss 8.8epss 0.10

    The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct XML external entity (XXE) attacks via a crafted PDF.

  • CVE-2026-15803HigAug 12, 2026
    risk 0.57cvss epss 0.00

    In Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsing untrusted XML-based RDF data or query results, permitting DOCTYPE declarations, external entity references, and external DTD loading. This is due to an…

  • CVE-2026-56817CriJul 21, 2026
    risk 0.57cvss 9.8epss 0.00

    Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that can deliver bytes to a Netty channel pipeline containing `XmlDecoder` can send XML with a…

  • CVE-2026-49875CriJun 12, 2026
    risk 0.57cvss 9.8epss 0.01

    Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12,…

  • CVE-2026-38429CriMay 5, 2026
    risk 0.57cvss 9.8epss 0.00

    OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature due to insecure XML parsing of user supplied .zip files containing a manifest.xml.

  • CVE-2026-36765HigApr 30, 2026
    risk 0.57cvss 8.8epss 0.00

    An XML external entity (XXE) vulnerability in the /designer/loadReport endpoint of SpringBlade v4.8.0 allows authenticated attackers to execute arbitrary code via injecting a crafted payload.

  • CVE-2025-65482CriJan 20, 2026
    risk 0.57cvss 9.8epss 0.00

    An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitrary code via uploading a crafted .docx file.

  • CVE-2023-7307HigAug 27, 2025
    risk 0.57cvss epss 0.01

    Sangfor Behavior Management System (also referred to as DC Management System in Chinese-language documentation) contains an XML external entity (XXE) injection vulnerability in the /src/sangforindex endpoint. A remote unauthenticated attacker can submit crafted XML data…

  • CVE-2025-36049HigJun 18, 2025
    risk 0.57cvss 8.8epss 0.01

    IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands.

  • CVE-2025-27523HigMay 15, 2025
    risk 0.57cvss 8.7epss 0.00

    XXE vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Device Manager: from 12-00 before 12-00-08, from 11-10 through 11-10-08, from 11-00 through 11-00-05, from 10-50 through 10-50-06.

  • CVE-2025-4639HigMay 14, 2025
    risk 0.57cvss epss 0.00

    CWE-611 Improper Restriction of XML External Entity Reference in the getDocumentBuilder() method of WebDav servlet in Peergos. This issue affects Peergos through version 1.1.0.

  • CVE-2023-38693CriMar 5, 2025
    risk 0.57cvss 9.8epss 0.01

    Lucee Server (or simply Lucee) is a dynamic, Java based, tag and scripting language used for rapid web application development. The Lucee REST endpoint is vulnerable to RCE via an XML XXE attack. This vulnerability is fixed in Lucee 5.4.3.2, 5.3.12.1, 5.3.7.59, 5.3.8.236, and…

  • CVE-2024-55875CriDec 12, 2024
    risk 0.57cvss 9.8epss 0.02

    http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 6.50.0.0, there is a potential XXE (XML External Entity Injection) vulnerability when http4k handling malicious XML contents within requests, which might allow attackers to read local sensitive…

  • CVE-2024-46455CriDec 9, 2024
    risk 0.57cvss 9.8epss 0.01

    unstructured v.0.14.2 and before is vulnerable to XML External Entity (XXE) via the XMLParser.