VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,372)

page 24 of 69
  • CVE-2026-21569HigJan 28, 2026
    risk 0.51cvss 7.9epss 0.00

    This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 7.1.0 of Crowd Data Center and Server. This XXE (XML External Entity Injection) vulnerability, with a CVSS Score of 7.9, allows an authenticated attacker to access local and remote…

  • CVE-2024-12476HigJan 17, 2025
    risk 0.51cvss 7.8epss 0.00

    CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure, impacts workstation integrity and potential remote code execution on the compromised computer, when specific crafted XML file is imported in the Web…

  • CVE-2024-53674HigNov 26, 2024
    risk 0.51cvss 7.3epss 0.47

    An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

  • CVE-2024-6893HigAug 8, 2024
    risk 0.51cvss 7.5epss 0.33

    The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This allows an unauthenticated attacker to read local files, perform server-side request forgery, and overwhelm the web server resources.

  • CVE-2024-3969HigMay 28, 2024
    risk 0.51cvss 7.8epss 0.01

    XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to remote code execution by parsing untrusted XML payload

  • CVE-2024-3486HigMay 15, 2024
    risk 0.51cvss 7.8epss 0.00

    XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to information disclosure and remote code execution.

  • CVE-2023-24187HigFeb 14, 2023
    risk 0.51cvss 7.8epss 0.01

    An XML External Entity (XXE) vulnerability in ureport v2.2.9 allows attackers to execute arbitrary code via uploading a crafted XML file to /ureport/designer/saveReportFile.

  • CVE-2022-45588HigFeb 3, 2023
    risk 0.51cvss 7.8epss 0.00

    All versions before R2022-09 of Talend's Remote Engine Gen 2 are potentially vulnerable to XML External Entity (XXE) type of attacks. Users should download the R2022-09 release or later and use it in place of the previous version. Talend Remote Engine Gen 1 and Talend Cloud…

  • CVE-2022-27873HigJul 29, 2022
    risk 0.51cvss 7.8epss 0.00

    An attacker can force the victim’s device to perform arbitrary HTTP requests in WAN through a malicious SVG file being parsed by Autodesk Fusion 360’s document parser. The vulnerability exists in the application’s ‘Insert SVG’ procedure. An attacker can also leverage…

  • CVE-2021-46365HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.02

    An issue in the Export function of Magnolia v6.2.3 and below allows attackers to execute XML External Entity attacks via a crafted XLF file.

  • CVE-2022-21220HigFeb 9, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper restriction of XML external entity for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-30201HigJul 9, 2021
    risk 0.51cvss 7.5epss 0.25

    The API /vsaWS/KaseyaWS.asmx can be used to submit XML to the system. When this XML is processed (external) entities are insecurely processed and fetched by the system and returned to the attacker. Detailed description Given the following request: ``` POST /vsaWS/KaseyaWS.asmx…

  • CVE-2014-5238HigJan 14, 2020
    risk 0.51cvss 7.8epss 0.02

    XML external entity (XXE) vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev11 and 7.6.x before 7.6.0-rev9 allows remote attackers to read arbitrary files and possibly other unspecified impact via a crafted OpenDocument Text document.

  • CVE-2019-8086HigOct 25, 2019
    risk 0.51cvss 7.5epss 0.23

    Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitive information disclosure.

  • CVE-2018-18980HigNov 6, 2018
    risk 0.51cvss 7.5epss 0.25

    An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the RequestXML parameter in a /devices/ProcessRequest.do GET request. For example, the attacker can trigger the transmission of local…

  • CVE-2016-9487HigJul 13, 2018
    risk 0.51cvss 7.8epss 0.01

    EpubCheck 4.0.1 does not properly restrict resolving external entities when parsing XML in EPUB files during validation. An attacker who supplies a specially crafted EPUB file may be able to exploit this behavior to read arbitrary files, or have the victim execute arbitrary…

  • CVE-2018-1000548HigJun 26, 2018
    risk 0.51cvss 7.8epss 0.02

    Umlet version < 14.3 contains a XML External Entity (XXE) vulnerability in File parsing that can result in disclosure of confidential data, denial of service, server side request forgery. This attack appear to be exploitable via Specially crafted UXF file. This vulnerability…

  • CVE-2018-1000546HigJun 26, 2018
    risk 0.51cvss 7.8epss 0.04

    Triplea version <= 1.9.0.0.10291 contains a XML External Entity (XXE) vulnerability in Importing game data that can result in Possible information disclosure, server-side request forgery, or remote code execution. This attack appear to be exploitable via Specially crafted game…

  • CVE-2018-1000542HigJun 26, 2018
    risk 0.51cvss 7.8epss 0.04

    netbeans-mmd-plugin version <= 1.4.3 contains a XML External Entity (XXE) vulnerability in MMD file import that can result in Possible information disclosure, server-side request forgery, or remote code execution. This attack appear to be exploitable via Specially crafted MMD…

  • CVE-2018-1000540HigJun 26, 2018
    risk 0.51cvss 7.8epss 0.02

    LoboEvolution version < 9b75694cedfa4825d4a2330abf2719d470c654cd contains a XML External Entity (XXE) vulnerability in XML Parsing when viewing the XML file in the browser that can result in disclosure of confidential data, denial of service, server side request forgery. This…