VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,331)

page 23 of 67
  • CVE-2026-55471CriJul 8, 2026
    risk 0.52cvss 9.1epss 0.00

    HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, org.hl7.fhir.utilities.XsltUtilities saxonTransform(...) overloads instantiated a bare net.sf.saxon.TransformerFactoryImpl() without ACCESS_EXTERNAL_DTD or…

  • CVE-2026-24400CriJan 26, 2026
    risk 0.52cvss 9.1epss 0.01

    AssertJ provides Fluent testing assertions for Java and the Java Virtual Machine (JVM). Starting in version 1.4.0 and prior to version 3.27.7, an XML External Entity (XXE) vulnerability exists in `org.assertj.core.util.xml.XmlStringPrettyFormatter`: the `toXmlDocument(String)`…

  • CVE-2025-46726CriMay 5, 2025
    risk 0.52cvss 9.1epss 0.01

    Langroid is a framework for building large-language-model-powered applications. Prior to version 0.53.4, a LLM application leveraging `XMLToolMessage` class may be exposed to untrusted XML input that could result in DoS and/or exposing local files with sensitive information.…

  • CVE-2024-40896CriDec 23, 2024
    risk 0.52cvss 9.1epss 0.01

    In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.

  • CVE-2024-4690HigOct 16, 2024
    risk 0.52cvss 8.0epss 0.00

    Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.

  • CVE-2024-4189HigOct 16, 2024
    risk 0.52cvss 8.0epss 0.00

    Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.

  • CVE-2024-4184HigOct 16, 2024
    risk 0.52cvss 8.0epss 0.00

    Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.

  • CVE-2024-25606HigFeb 20, 2024
    risk 0.52cvss 8.0epss 0.01

    XXE vulnerability in Liferay Portal 7.2.0 through 7.4.3.7, and older unsupported versions, and Liferay DXP 7.4 before update 4, 7.3 before update 12, 7.2 before fix pack 20, and older unsupported versions allows attackers with permission to deploy widgets/portlets/extensions to…

  • CVE-2022-42341HigOct 14, 2022
    risk 0.52cvss 7.5epss 0.36

    Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary file system read. Exploitation of this issue does not require user…

  • CVE-2021-21658CriMay 25, 2021
    risk 0.52cvss 9.1epss 0.02

    Jenkins Nuget Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2013-4333CriJan 24, 2020
    risk 0.52cvss 9.1epss 0.02

    OpenPNE 3 versions 3.8.7, 3.6.11, 3.4.21.1, 3.2.7.6, 3.0.8.5 has an External Entity Injection Vulnerability

  • CVE-2019-9757HigOct 29, 2019
    risk 0.52cvss 7.5epss 0.37

    An issue was discovered in LabKey Server 19.1.0. Sending an SVG containing an XXE payload to the endpoint visualization-exportImage.view or visualization-exportPDF.view allows local files to be read.

  • CVE-2017-6323HigApr 16, 2018
    risk 0.52cvss 8.0epss 0.01

    The Symantec Management Console prior to ITMS 8.1 RU1, ITMS 8.0_POST_HF6, and ITMS 7.6_POST_HF7 has an issue whereby XML input containing a reference to an external entity is processed by a weakly configured XML parser. This attack may lead to the disclosure of confidential…

  • CVE-2017-6662HigJun 26, 2017
    risk 0.52cvss 8.0epss 0.02

    A vulnerability in the web-based user interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker read and write access to information stored in the affected system as well as perform remote code…

  • CVE-2016-10127CriMar 3, 2017
    risk 0.52cvss 9.0epss 0.02

    PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response.

  • CVE-2016-4312HigFeb 17, 2017
    risk 0.52cvss 7.5epss 0.06

    XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 before WSO2-CARBON-PATCH-4.4.0-0231 allows remote authenticated users with access to XACML features to read arbitrary files, cause a denial of service, conduct server-side request…

  • CVE-2026-21569HigJan 28, 2026
    risk 0.51cvss 7.9epss 0.00

    This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 7.1.0 of Crowd Data Center and Server. This XXE (XML External Entity Injection) vulnerability, with a CVSS Score of 7.9, allows an authenticated attacker to access local and remote…

  • CVE-2024-12476HigJan 17, 2025
    risk 0.51cvss 7.8epss 0.00

    CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure, impacts workstation integrity and potential remote code execution on the compromised computer, when specific crafted XML file is imported in the Web…

  • CVE-2024-53674HigNov 26, 2024
    risk 0.51cvss 7.3epss 0.47

    An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

  • CVE-2024-6893HigAug 8, 2024
    risk 0.51cvss 7.5epss 0.33

    The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This allows an unauthenticated attacker to read local files, perform server-side request forgery, and overwhelm the web server resources.