VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,372)

page 35 of 69
  • CVE-2025-10816HigSep 22, 2025
    risk 0.47cvss 7.3epss 0.01

    A security flaw has been discovered in Jinher OA 2.0. This affects an unknown part of the file /c6/Jhsoft.Web.module/ToolBar/GetWordFileName.aspx/?text=GetUrl&style=add of the component XML Handler. Performing manipulation results in xml external entity reference. The attack may…

  • CVE-2025-10092HigSep 8, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown function of the file /c6/Jhsoft.Web.projectmanage/TaskManage/AddTask.aspx/?Type=add of the component XML Handler. The manipulation results in xml external entity reference. The attack can be executed…

  • CVE-2025-10091HigSep 8, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in Jinher OA up to 1.2. This affects an unknown function of the file /c6/Jhsoft.Web.projectmanage/ProjectManage/XmlHttp.aspx/?Type=add of the component XML Handler. The manipulation leads to xml external entity reference. Remote exploitation of the…

  • CVE-2025-7824HigJul 19, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in Jinher OA 1.1. It has been rated as problematic. This issue affects some unknown processing of the file XmlHttp.aspx. The manipulation leads to xml external entity reference. The attack may be initiated remotely. The exploit has been disclosed to the…

  • CVE-2025-7823HigJul 19, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in Jinher OA 1.2. It has been declared as problematic. This vulnerability affects unknown code of the file ProjectScheduleDelete.aspx. The manipulation leads to xml external entity reference. The attack can be initiated remotely. The exploit has been…

  • CVE-2025-7523HigJul 13, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in Jinher OA 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /c6/Jhsoft.Web.message/ToolBar/DelTemp.aspx. The manipulation leads to xml external entity reference. The attack may be launched remotely.…

  • CVE-2024-52806HigDec 2, 2024
    risk 0.47cvss 8.3epss 0.00

    SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. When loading an (untrusted) XML document, for example the SAMLResponse, it's possible to induce an XXE. This vulnerability is fixed in 4.6.14 and 5.0.0-alpha.18.

  • CVE-2023-49110HigJun 20, 2024
    risk 0.47cvss 7.2epss 0.01

    When the Kiuwan Local Analyzer uploads the scan results to the Kiuwan SAST web application (either on-premises or cloud/SaaS solution), the transmitted data consists of a ZIP archive containing several files, some of them in the XML file format. During Kiuwan's server-side…

  • CVE-2024-30043MedMay 14, 2024
    risk 0.47cvss 6.5epss 0.55

    Microsoft SharePoint Server Information Disclosure Vulnerability

  • CVE-2023-6280HigDec 19, 2023
    risk 0.47cvss 7.2epss 0.01

    An XXE (XML External Entity) vulnerability has been detected in 52North WPS affecting versions prior to 4.0.0-beta.11. This vulnerability allows the use of external entities in its WebProcessingService servlet for an attacker to retrieve files by making HTTP requests to the…

  • CVE-2022-36969HigMar 29, 2023
    risk 0.47cvss 7.1epss 0.14

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a…

  • CVE-2022-39954HigFeb 16, 2023
    risk 0.47cvss 7.3epss 0.01

    An improper restriction of xml external entity reference in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.7, FortiNAC version 9.1.0 through 9.1.8, FortiNAC version 8.8.0 through 8.8.11, FortiNAC version 8.7.0 through 8.7.6, FortiNAC version…

  • CVE-2021-33208HigMar 30, 2022
    risk 0.47cvss 7.2epss 0.01

    The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA allows XXE attacks via a malicious XML configuration file.

  • CVE-2021-42194HigMar 20, 2022
    risk 0.47cvss 7.2epss 0.01

    The wechat_return function in /controller/Index.php of EyouCms V1.5.4-UTF8-SP3 passes the user's input directly into the simplexml_ load_ String function, which itself does not prohibit external entities, triggering a XML external entity (XXE) injection vulnerability.

  • CVE-2021-38584HigAug 11, 2021
    risk 0.47cvss 7.2epss 0.01

    The WHM Locale Upload feature in cPanel before 98.0.1 allows XXE attacks (SEC-585).

  • CVE-2021-22158HigApr 6, 2021
    risk 0.47cvss 7.2epss 0.01

    The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is vulnerable to XML external entity (XXE) injection in the Web Console. The vulnerability requires admin user privileges and knowledge of the XML file's encryption key to successfully exploit. All…

  • CVE-2021-21517HigMar 1, 2021
    risk 0.47cvss 7.2epss 0.01

    SRS Policy Manager 6.X is affected by an XML External Entity Injection (XXE) vulnerability due to a misconfigured XML parser that processes user-supplied DTD input without sufficient validation. A remote unauthenticated attacker can potentially exploit this vulnerability to read…

  • CVE-2020-15352HigOct 27, 2020
    risk 0.47cvss 7.2epss 0.03

    An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) before 9.1R9 allows remote authenticated admins to conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

  • CVE-2020-17376HigAug 26, 2020
    risk 0.47cvss 8.3epss 0.02

    An issue was discovered in Guest.migrate in virt/libvirt/guest.py in OpenStack Nova before 19.3.1, 20.x before 20.3.1, and 21.0.0. By performing a soft reboot of an instance that has previously undergone live migration, a user may gain access to destination host devices that…

  • CVE-2020-12719HigMay 8, 2020
    risk 0.47cvss 7.2epss 0.01

    XXE during an EventPublisher update can occur in Management Console in WSO2 API Manager 3.0.0 and earlier, API Manager Analytics 2.5.0 and earlier, API Microgateway 2.2.0, Enterprise Integrator 6.4.0 and earlier, IS as Key Manager 5.9.0 and earlier, Identity Server 5.9.0 and…