CWE-611
Improper Restriction of XML External Entity Reference
Description
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-221
CVEs mapped to this weakness (1,331)
page 3 of 67| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-1000124 | Cri | 0.65 | 10.0 | 0.02 | Mar 13, 2018 | I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_string) that can result in an attacker reading the contents of a file and SSRF. This attack appear to be exploitable via posting… | ||
| CVE-2017-13706 | Cri | 0.65 | 9.9 | 0.02 | Oct 10, 2017 | XML external entity (XXE) vulnerability in the import package functionality of the deployment module in Lansweeper before 6.0.100.67 allows remote authenticated users to obtain sensitive information, cause a denial of service, conduct server-side request forgery (SSRF) attacks,… | ||
| CVE-2017-7664 | Cri | 0.65 | 10.0 | 0.02 | Jul 17, 2017 | Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0. | ||
| CVE-2017-8110 | Cri | 0.65 | 10.0 | 0.01 | Apr 25, 2017 | www.modified-shop.org modified eCommerce Shopsoftware 2.0.2.2 rev 10690 has XXE in api/it-recht-kanzlei/api-it-recht-kanzlei.php. | ||
| CVE-2026-51080 | Cri | 0.64 | 9.8 | 0.00 | Jul 17, 2026 | libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability. | ||
| CVE-2026-6653 | Cri | 0.64 | 9.8 | 0.00 | Jun 22, 2026 | Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling. | ||
| CVE-2018-25142 | Cri | 0.64 | 9.8 | 0.00 | Dec 24, 2025 | NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an… | ||
| CVE-2024-55081 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2024 | An XML External Entity (XXE) injection vulnerability in the component /datagrip/upload of Chat2DB v0.3.5 allows attackers to execute arbitrary code via supplying a crafted XML input. | ||
| CVE-2024-51136 | Cri | 0.64 | 9.8 | 0.01 | Nov 4, 2024 | An XML External Entity (XXE) vulnerability in Dmoz2CSV in openimaj v1.3.10 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted XML file. | ||
| CVE-2024-7098 | Cri | 0.64 | 9.8 | 0.00 | Sep 16, 2024 | Improper Restriction of XML External Entity Reference vulnerability in SFS Consulting ww.Winsure allows XML Injection. This issue affects ww.Winsure: before 4.6.2. | ||
| CVE-2024-21082 | Cri | 0.64 | 9.8 | 0.01 | Apr 16, 2024 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that are affected are 7.0.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | ||
| CVE-2023-26999 | Cri | 0.64 | 9.8 | 0.01 | Jan 9, 2024 | An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted file. | ||
| CVE-2023-52252 | Cri | 0.64 | 9.8 | 0.01 | Dec 30, 2023 | Unified Remote 3.13.0 allows remote attackers to execute arbitrary Lua code because of a wildcarded Access-Control-Allow-Origin for the Remote upload endpoint. | ||
| CVE-2023-46265 | Cri | 0.64 | 9.8 | 0.04 | Dec 19, 2023 | An unauthenticated could abuse a XXE vulnerability in the Smart Device Server to leak data or perform a Server-Side Request Forgery (SSRF). | ||
| CVE-2023-49733 | Cri | 0.64 | 9.8 | 0.01 | Nov 30, 2023 | Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue. | ||
| CVE-2023-49656 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2023 | Jenkins MATLAB Plugin 2.11.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | ||
| CVE-2022-48565 | Cri | 0.64 | 9.8 | 0.04 | Aug 22, 2023 | An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities. | ||
| CVE-2023-32567 | Cri | 0.64 | 9.8 | 0.03 | Aug 10, 2023 | Ivanti Avalanche decodeToMap XML External Entity Processing. Fixed in version 6.4.1.236 | ||
| CVE-2023-20918 | Cri | 0.64 | 9.8 | 0.01 | Jul 13, 2023 | In getPendingIntentLaunchFlags of ActivityOptions.java, there is a possible elevation of privilege due to a confused deputy with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-27874 | Cri | 0.64 | 9.9 | 0.01 | Mar 21, 2023 | IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands. IBM X-Force ID: 249845. |
- risk 0.65cvss 10.0epss 0.02
I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_string) that can result in an attacker reading the contents of a file and SSRF. This attack appear to be exploitable via posting…
- risk 0.65cvss 9.9epss 0.02
XML external entity (XXE) vulnerability in the import package functionality of the deployment module in Lansweeper before 6.0.100.67 allows remote authenticated users to obtain sensitive information, cause a denial of service, conduct server-side request forgery (SSRF) attacks,…
- risk 0.65cvss 10.0epss 0.02
Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0.
- risk 0.65cvss 10.0epss 0.01
www.modified-shop.org modified eCommerce Shopsoftware 2.0.2.2 rev 10690 has XXE in api/it-recht-kanzlei/api-it-recht-kanzlei.php.
- risk 0.64cvss 9.8epss 0.00
libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability.
- risk 0.64cvss 9.8epss 0.00
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.
- risk 0.64cvss 9.8epss 0.00
NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an…
- risk 0.64cvss 9.8epss 0.01
An XML External Entity (XXE) injection vulnerability in the component /datagrip/upload of Chat2DB v0.3.5 allows attackers to execute arbitrary code via supplying a crafted XML input.
- risk 0.64cvss 9.8epss 0.01
An XML External Entity (XXE) vulnerability in Dmoz2CSV in openimaj v1.3.10 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted XML file.
- risk 0.64cvss 9.8epss 0.00
Improper Restriction of XML External Entity Reference vulnerability in SFS Consulting ww.Winsure allows XML Injection. This issue affects ww.Winsure: before 4.6.2.
- risk 0.64cvss 9.8epss 0.01
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that are affected are 7.0.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…
- risk 0.64cvss 9.8epss 0.01
An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted file.
- risk 0.64cvss 9.8epss 0.01
Unified Remote 3.13.0 allows remote attackers to execute arbitrary Lua code because of a wildcarded Access-Control-Allow-Origin for the Remote upload endpoint.
- risk 0.64cvss 9.8epss 0.04
An unauthenticated could abuse a XXE vulnerability in the Smart Device Server to leak data or perform a Server-Side Request Forgery (SSRF).
- risk 0.64cvss 9.8epss 0.01
Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue.
- risk 0.64cvss 9.8epss 0.01
Jenkins MATLAB Plugin 2.11.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- risk 0.64cvss 9.8epss 0.04
An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.
- risk 0.64cvss 9.8epss 0.03
Ivanti Avalanche decodeToMap XML External Entity Processing. Fixed in version 6.4.1.236
- risk 0.64cvss 9.8epss 0.01
In getPendingIntentLaunchFlags of ActivityOptions.java, there is a possible elevation of privilege due to a confused deputy with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.64cvss 9.9epss 0.01
IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands. IBM X-Force ID: 249845.