CWE-611
Improper Restriction of XML External Entity Reference
Description
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-221
CVEs mapped to this weakness (1,331)
page 40 of 67| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-4338 | Med | 0.44 | 6.8 | 0.00 | May 22, 2025 | Lantronix Device installer is vulnerable to XML external entity (XXE) attacks in configuration files read from the network device. An attacker could obtain credentials, access these network devices, and modify their configurations. An attacker may also gain access to the host… | ||
| CVE-2025-25036 | Med | 0.44 | 6.8 | 0.00 | Mar 21, 2025 | Improper Restriction of XML External Entity Reference vulnerability in Jalios JPlatform allows XML Injection.This issue affects all versions of JPlatform 10 before 10.0.8 (SP8). | ||
| CVE-2023-42445 | Med | 0.44 | 6.8 | 0.01 | Oct 6, 2023 | Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, when Gradle parses XML files, resolving XML external entities is not disabled. Combined with an Out Of Band XXE attack (OOB-XXE), just parsing XML can lead to… | ||
| CVE-2023-26461 | Med | 0.44 | 6.8 | 0.01 | Mar 14, 2023 | SAP NetWeaver allows (SAP Enterprise Portal) - version 7.50, allows an authenticated attacker with sufficient privileges to access the XML parser which can submit a crafted XML file which when parsed will enable them to access but not modify sensitive files and data. It allows… | ||
| CVE-2023-1288 | Med | 0.44 | 6.8 | 0.01 | Mar 9, 2023 | An XML External Entity injection (XXE) vulnerability in ENOVIA Live Collaboration V6R2013xE allows an attacker to read local files on the server. | ||
| CVE-2022-22795 | Med | 0.44 | 6.8 | 0.01 | Mar 10, 2022 | Signiant - Manager+Agents XML External Entity (XXE) - Extract internal files of the affected machine An attacker can read all the system files, the product is running with root on Linux systems and nt/authority on windows systems, which allows him to access and extract any file… | ||
| CVE-2020-13883 | — | Med | 0.44 | 6.7 | 0.01 | Jun 6, 2020 | In WSO2 API Manager 3.0.0 and earlier, WSO2 API Microgateway 2.2.0, and WSO2 IS as Key Manager 5.9.0 and earlier, Management Console allows XXE during addition or update of a Lifecycle. | |
| CVE-2020-1975 | Med | 0.44 | 6.8 | 0.01 | Feb 12, 2020 | Missing XML validation vulnerability in the PAN-OS web interface on Palo Alto Networks PAN-OS software allows authenticated users to inject arbitrary XML that results in privilege escalation. This issue affects PAN-OS 8.1 versions earlier than PAN-OS 8.1.12 and PAN-OS 9.0… | ||
| CVE-2026-33913 | Hig | 0.43 | 7.7 | 0.00 | Mar 25, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an authenticated user with access to the Carecoordination module can upload a crafted CCDA document containing `<xi:include… | ||
| CVE-2025-32138 | Med | 0.43 | 6.6 | 0.01 | Apr 4, 2025 | Improper Restriction of XML External Entity Reference vulnerability in supsystic Easy Google Maps google-maps-easy allows XML Injection.This issue affects Easy Google Maps: from n/a through <= 1.11.18. | ||
| CVE-2025-31487 | Hig | 0.43 | 7.7 | 0.00 | Apr 3, 2025 | The XWiki JIRA extension provides various integration points between XWiki and JIRA (macros, UI, CKEditor plugin). If the JIRA macro is installed, any logged in XWiki user could edit his/her user profile wiki page and use that JIRA macro, specifying a fake JIRA URL that returns… | ||
| CVE-2023-28340 | Med | 0.43 | 6.5 | 0.03 | Apr 11, 2023 | Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack. | ||
| CVE-2023-27480 | Hig | 0.43 | 7.7 | 0.01 | Mar 7, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with edit rights on a document can trigger an XAR import on a forged XAR file, leading to the ability to display the content of any file on the… | ||
| CVE-2022-22835 | Med | 0.43 | 6.5 | 0.14 | Mar 10, 2022 | An issue was discovered in OverIT Geocall before version 8.0. An authenticated user who has the Test Trasformazione XSL functionality enabled can exploit a XXE vulnerability to read arbitrary files from the filesystem. | ||
| CVE-2021-40439 | Med | 0.43 | 6.5 | 0.03 | Oct 7, 2021 | Apache OpenOffice has a dependency on expat software. Versions prior to 2.1.0 were subject to CVE-2013-0340 a "Billion Laughs" entity expansion denial of service attack and exploit via crafted XML files. ODF files consist of a set of XML files. All versions of Apache OpenOffice… | ||
| CVE-2021-33813 | Hig | 0.43 | 7.5 | 0.19 | Jun 16, 2021 | An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request. | ||
| CVE-2020-25649 | Hig | 0.43 | 7.5 | 0.18 | Dec 3, 2020 | A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity. | ||
| CVE-2020-7032 | Med | 0.43 | 6.5 | 0.04 | Nov 13, 2020 | An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. Affected versions of Avaya WebLM include: 7.0 through 7.1.3.6… | ||
| CVE-2020-24656 | Med | 0.43 | 6.5 | 0.04 | Aug 26, 2020 | Maltego before 4.2.12 allows XXE attacks. | ||
| CVE-2020-13692 | Hig | 0.43 | 7.7 | 0.04 | Jun 4, 2020 | PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE. |
- risk 0.44cvss 6.8epss 0.00
Lantronix Device installer is vulnerable to XML external entity (XXE) attacks in configuration files read from the network device. An attacker could obtain credentials, access these network devices, and modify their configurations. An attacker may also gain access to the host…
- risk 0.44cvss 6.8epss 0.00
Improper Restriction of XML External Entity Reference vulnerability in Jalios JPlatform allows XML Injection.This issue affects all versions of JPlatform 10 before 10.0.8 (SP8).
- risk 0.44cvss 6.8epss 0.01
Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, when Gradle parses XML files, resolving XML external entities is not disabled. Combined with an Out Of Band XXE attack (OOB-XXE), just parsing XML can lead to…
- risk 0.44cvss 6.8epss 0.01
SAP NetWeaver allows (SAP Enterprise Portal) - version 7.50, allows an authenticated attacker with sufficient privileges to access the XML parser which can submit a crafted XML file which when parsed will enable them to access but not modify sensitive files and data. It allows…
- risk 0.44cvss 6.8epss 0.01
An XML External Entity injection (XXE) vulnerability in ENOVIA Live Collaboration V6R2013xE allows an attacker to read local files on the server.
- risk 0.44cvss 6.8epss 0.01
Signiant - Manager+Agents XML External Entity (XXE) - Extract internal files of the affected machine An attacker can read all the system files, the product is running with root on Linux systems and nt/authority on windows systems, which allows him to access and extract any file…
- risk 0.44cvss 6.7epss 0.01
In WSO2 API Manager 3.0.0 and earlier, WSO2 API Microgateway 2.2.0, and WSO2 IS as Key Manager 5.9.0 and earlier, Management Console allows XXE during addition or update of a Lifecycle.
- risk 0.44cvss 6.8epss 0.01
Missing XML validation vulnerability in the PAN-OS web interface on Palo Alto Networks PAN-OS software allows authenticated users to inject arbitrary XML that results in privilege escalation. This issue affects PAN-OS 8.1 versions earlier than PAN-OS 8.1.12 and PAN-OS 9.0…
- risk 0.43cvss 7.7epss 0.00
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an authenticated user with access to the Carecoordination module can upload a crafted CCDA document containing `<xi:include…
- risk 0.43cvss 6.6epss 0.01
Improper Restriction of XML External Entity Reference vulnerability in supsystic Easy Google Maps google-maps-easy allows XML Injection.This issue affects Easy Google Maps: from n/a through <= 1.11.18.
- risk 0.43cvss 7.7epss 0.00
The XWiki JIRA extension provides various integration points between XWiki and JIRA (macros, UI, CKEditor plugin). If the JIRA macro is installed, any logged in XWiki user could edit his/her user profile wiki page and use that JIRA macro, specifying a fake JIRA URL that returns…
- risk 0.43cvss 6.5epss 0.03
Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.
- risk 0.43cvss 7.7epss 0.01
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with edit rights on a document can trigger an XAR import on a forged XAR file, leading to the ability to display the content of any file on the…
- risk 0.43cvss 6.5epss 0.14
An issue was discovered in OverIT Geocall before version 8.0. An authenticated user who has the Test Trasformazione XSL functionality enabled can exploit a XXE vulnerability to read arbitrary files from the filesystem.
- risk 0.43cvss 6.5epss 0.03
Apache OpenOffice has a dependency on expat software. Versions prior to 2.1.0 were subject to CVE-2013-0340 a "Billion Laughs" entity expansion denial of service attack and exploit via crafted XML files. ODF files consist of a set of XML files. All versions of Apache OpenOffice…
- risk 0.43cvss 7.5epss 0.19
An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.
- risk 0.43cvss 7.5epss 0.18
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
- risk 0.43cvss 6.5epss 0.04
An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. Affected versions of Avaya WebLM include: 7.0 through 7.1.3.6…
- risk 0.43cvss 6.5epss 0.04
Maltego before 4.2.12 allows XXE attacks.
- risk 0.43cvss 7.7epss 0.04
PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.