VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,372)

page 26 of 69
  • CVE-2021-30137HigSep 15, 2021
    risk 0.50cvss 7.7epss 0.01

    Assyst 10 SP7.5 has authenticated XXE leading to SSRF via XML unmarshalling. The application allows users to send JSON or XML data to the server. It was possible to inject malicious XML data through several access points.

  • CVE-2020-15418HigJul 28, 2020
    risk 0.50cvss 7.5epss 0.09

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSRSReport class. Due to the improper…

  • CVE-2020-4509HigJun 4, 2020
    risk 0.50cvss 7.6epss 0.02

    IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 182364.

  • CVE-2020-2120HigFeb 12, 2020
    risk 0.50cvss 8.8epss 0.01

    Jenkins FitNesse Plugin 1.30 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2020-2115HigFeb 12, 2020
    risk 0.50cvss 8.8epss 0.01

    Jenkins NUnit Plugin 0.25 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2020-2092HigJan 15, 2020
    risk 0.50cvss 8.8epss 0.01

    Jenkins Robot Framework Plugin 2.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing users with Job/Configure to have Jenkins parse crafted XML documents.

  • CVE-2011-3600HigNov 26, 2019
    risk 0.50cvss 7.5epss 0.16

    The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with executable payloads that discloses the contents of files in the filesystem. In addition, it can also be used to probe for open…

  • CVE-2019-10172HigNov 18, 2019
    risk 0.50cvss 7.5epss 0.17

    A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.

  • CVE-2019-12331HigNov 7, 2019
    risk 0.50cvss 8.8epss 0.01

    PHPOffice PhpSpreadsheet before 1.8.0 has an XXE issue. The XmlScanner decodes the sheet1.xml from an .xlsx to utf-8 if something else than UTF-8 is declared in the header. This was a security measurement to prevent CVE-2018-19277 but the fix is not sufficient. By…

  • CVE-2019-18213HigOct 23, 2019
    risk 0.50cvss 8.8epss 0.02

    XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows XXE via a crafted XML document, with resultant SSRF (as well as SMB connection initiation that can lead to NetNTLM…

  • CVE-2019-16174HigSep 9, 2019
    risk 0.50cvss 8.8epss 0.02

    An XML injection vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to import specially crafted XML files and execute code or compromise data integrity.

  • CVE-2018-17169HigApr 23, 2019
    risk 0.50cvss 7.7epss 0.01

    An XML external entity (XXE) vulnerability in PrinterOn version 4.1.4 and lower allows remote authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

  • CVE-2018-1821HigDec 13, 2018
    risk 0.50cvss 7.1epss 0.13

    IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID:…

  • CVE-2018-6670HigJun 7, 2018
    risk 0.50cvss 7.6epss 0.01

    External Entity Attack vulnerability in the ePO extension in McAfee Common UI (CUI) 2.0.2 allows remote authenticated users to view confidential information via a crafted HTTP request parameter.

  • CVE-2018-10613HigJun 4, 2018
    risk 0.50cvss 7.5epss 0.15

    Multiple variants of XML External Entity (XXE) attacks may be used to exfiltrate data from the host Windows platform in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior.

  • CVE-2017-11272HigAug 11, 2017
    risk 0.50cvss 7.5epss 0.04

    Adobe Digital Editions 4.5.4 and earlier has a security bypass vulnerability.

  • CVE-2014-0225HigMay 25, 2017
    risk 0.50cvss 8.8epss 0.02

    When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

  • CVE-2016-7459HigDec 29, 2016
    risk 0.50cvss 7.7epss 0.02

    VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authenticated users to read arbitrary files via a (1) Log Browser, (2) Distributed Switch setup, or (3) Content Library XML document containing an external entity declaration in conjunction with an entity…

  • CVE-2016-5851HigDec 21, 2016
    risk 0.50cvss 8.8epss 0.02

    python-docx before 0.8.6 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted document.

  • CVE-2026-89260HigSep 11, 2026
    risk 0.49cvss 7.5epss 0.00

    MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at POST /wechat/wechatCheck. The WechatRestApi.index() method passes the raw request body to SignUtil.xmlToMap(), which uses an unhardened dom4j SAXReader without DTD or…