VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,372)

page 25 of 69
  • CVE-2018-1247HigMay 8, 2018
    risk 0.51cvss 7.1epss 0.20

    RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability. This could potentially allow admin users to cause a denial of service or extract server data via injecting a maliciously crafted DTD in an XML file submitted…

  • CVE-2017-1000498HigJan 3, 2018
    risk 0.51cvss 7.8epss 0.02

    AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and possibly remote code execution

  • CVE-2017-9096HigNov 8, 2017
    risk 0.51cvss 8.8epss 0.10

    The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct XML external entity (XXE) attacks via a crafted PDF.

  • CVE-2016-5002HigOct 27, 2017
    risk 0.51cvss 7.8epss 0.16

    XML external entity (XXE) vulnerability in the Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted DTD.

  • CVE-2016-4434HigSep 30, 2017
    risk 0.51cvss 7.8epss 0.07

    Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other file formats, a…

  • CVE-2017-6055HigFeb 17, 2017
    risk 0.51cvss 7.8epss 0.02

    XML external entity (XXE) vulnerability in eParakstitajs 3 before 1.3.9 and eParaksts Java lib before 2.5.13 allows remote attackers to read arbitrary files or possibly have unspecified other impact via a crafted edoc file.

  • CVE-2016-2175HigJun 1, 2016
    risk 0.51cvss 7.8epss 0.07

    Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.

  • CVE-2026-16432HigSep 14, 2026
    risk 0.50cvss 7.7epss 0.00

    IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage PxXMLInput operator could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.

  • CVE-2026-81832HigSep 4, 2026
    risk 0.50cvss 7.7epss 0.00

    IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 SAP Adapter is vulnerable to an XML external entity (XXE) attack.

  • CVE-2026-54079HigJul 29, 2026
    risk 0.50cvss —epss 0.00

    veraPDF validation provides PDF/A and PDF/UA validation, feature reporting, and metadata repair. From 1.17.35 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity (XXE) vulnerability in validation-model/src/main/java/org/verapdf/gf/model/impl/pd/GFPDAcroFo…

  • CVE-2026-2253HigMay 27, 2026
    risk 0.50cvss 7.7epss 0.00

    Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, does not prevent certain XML parsers from resolving external entities.

  • CVE-2025-53689HigJul 14, 2025
    risk 0.50cvss 8.8epss 0.00

    Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Java 11, beta…

  • CVE-2025-48882HigMay 30, 2025
    risk 0.50cvss —epss 0.00

    PHPOffice Math is a library that provides a set of classes to manipulate different formula file formats. Prior to version 0.3.0, loading XML data using the standard `libxml` extension and the `LIBXML_DTDLOAD` flag without additional filtration, leads to XXE. Version 0.3.0 fixes…

  • CVE-2024-52596HigDec 2, 2024
    risk 0.50cvss —epss 0.01

    SimpleSAMLphp xml-common is a common classes for handling XML-structures. When loading an (untrusted) XML document, for example the SAMLResponse, it's possible to induce an XXE. This vulnerability is fixed in 1.19.0.

  • CVE-2024-45048HigAug 28, 2024
    risk 0.50cvss 8.8epss 0.01

    PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions are subject to a bypassing of a filter which allows for an XXE-attack. This in turn allows attacker to obtain contents of local files, even if error reporting is muted. This…

  • CVE-2023-48362HigJul 24, 2024
    risk 0.50cvss 8.8epss 0.01

    XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands via a malicious XML file. Users are recommended to upgrade to version 1.21.2, which fixes this issue.

  • CVE-2023-50168HigMar 14, 2024
    risk 0.50cvss 7.7epss 0.00

    Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.

  • CVE-2023-41933HigSep 6, 2023
    risk 0.50cvss 8.8epss 0.01

    Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2023-32706HigJun 1, 2023
    risk 0.50cvss 7.7epss 0.01

    On Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, an unauthenticated attacker can send specially-crafted messages to the XML parser within SAML authentication to cause a denial of service in the Splunk daemon.

  • CVE-2021-42776HigDec 1, 2021
    risk 0.50cvss 7.7epss 0.01

    CloverDX Server before 5.11.2 and and 5.12.x before 5.12.1 allows XXE during configuration import.