VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,331)

page 3 of 67
  • CVE-2018-1000124CriMar 13, 2018
    risk 0.65cvss 10.0epss 0.02

    I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_string) that can result in an attacker reading the contents of a file and SSRF. This attack appear to be exploitable via posting…

  • CVE-2017-13706CriOct 10, 2017
    risk 0.65cvss 9.9epss 0.02

    XML external entity (XXE) vulnerability in the import package functionality of the deployment module in Lansweeper before 6.0.100.67 allows remote authenticated users to obtain sensitive information, cause a denial of service, conduct server-side request forgery (SSRF) attacks,…

  • CVE-2017-7664CriJul 17, 2017
    risk 0.65cvss 10.0epss 0.02

    Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0.

  • CVE-2017-8110CriApr 25, 2017
    risk 0.65cvss 10.0epss 0.01

    www.modified-shop.org modified eCommerce Shopsoftware 2.0.2.2 rev 10690 has XXE in api/it-recht-kanzlei/api-it-recht-kanzlei.php.

  • CVE-2026-51080CriJul 17, 2026
    risk 0.64cvss 9.8epss 0.00

    libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability.

  • CVE-2026-6653CriJun 22, 2026
    risk 0.64cvss 9.8epss 0.00

    Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.

  • CVE-2018-25142CriDec 24, 2025
    risk 0.64cvss 9.8epss 0.00

    NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an…

  • CVE-2024-55081CriDec 19, 2024
    risk 0.64cvss 9.8epss 0.01

    An XML External Entity (XXE) injection vulnerability in the component /datagrip/upload of Chat2DB v0.3.5 allows attackers to execute arbitrary code via supplying a crafted XML input.

  • CVE-2024-51136CriNov 4, 2024
    risk 0.64cvss 9.8epss 0.01

    An XML External Entity (XXE) vulnerability in Dmoz2CSV in openimaj v1.3.10 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted XML file.

  • CVE-2024-7098CriSep 16, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Restriction of XML External Entity Reference vulnerability in SFS Consulting ww.Winsure allows XML Injection. This issue affects ww.Winsure: before 4.6.2.

  • CVE-2024-21082CriApr 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that are affected are 7.0.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…

  • CVE-2023-26999CriJan 9, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted file.

  • CVE-2023-52252CriDec 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Unified Remote 3.13.0 allows remote attackers to execute arbitrary Lua code because of a wildcarded Access-Control-Allow-Origin for the Remote upload endpoint.

  • CVE-2023-46265CriDec 19, 2023
    risk 0.64cvss 9.8epss 0.04

    An unauthenticated could abuse a XXE vulnerability in the Smart Device Server to leak data or perform a Server-Side Request Forgery (SSRF).

  • CVE-2023-49733CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue.

  • CVE-2023-49656CriNov 29, 2023
    risk 0.64cvss 9.8epss 0.01

    Jenkins MATLAB Plugin 2.11.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-48565CriAug 22, 2023
    risk 0.64cvss 9.8epss 0.04

    An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.

  • CVE-2023-32567CriAug 10, 2023
    risk 0.64cvss 9.8epss 0.03

    Ivanti Avalanche decodeToMap XML External Entity Processing. Fixed in version 6.4.1.236

  • CVE-2023-20918CriJul 13, 2023
    risk 0.64cvss 9.8epss 0.01

    In getPendingIntentLaunchFlags of ActivityOptions.java, there is a possible elevation of privilege due to a confused deputy with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-27874CriMar 21, 2023
    risk 0.64cvss 9.9epss 0.01

    IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands. IBM X-Force ID: 249845.