VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,331)

page 40 of 67
  • CVE-2025-4338MedMay 22, 2025
    risk 0.44cvss 6.8epss 0.00

    Lantronix Device installer is vulnerable to XML external entity (XXE) attacks in configuration files read from the network device. An attacker could obtain credentials, access these network devices, and modify their configurations. An attacker may also gain access to the host…

  • CVE-2025-25036MedMar 21, 2025
    risk 0.44cvss 6.8epss 0.00

    Improper Restriction of XML External Entity Reference vulnerability in Jalios JPlatform allows XML Injection.This issue affects all versions of JPlatform 10 before 10.0.8 (SP8).

  • CVE-2023-42445MedOct 6, 2023
    risk 0.44cvss 6.8epss 0.01

    Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, when Gradle parses XML files, resolving XML external entities is not disabled. Combined with an Out Of Band XXE attack (OOB-XXE), just parsing XML can lead to…

  • CVE-2023-26461MedMar 14, 2023
    risk 0.44cvss 6.8epss 0.01

    SAP NetWeaver allows (SAP Enterprise Portal) - version 7.50, allows an authenticated attacker with sufficient privileges to access the XML parser which can submit a crafted XML file which when parsed will enable them to access but not modify sensitive files and data. It allows…

  • CVE-2023-1288MedMar 9, 2023
    risk 0.44cvss 6.8epss 0.01

    An XML External Entity injection (XXE) vulnerability in ENOVIA Live Collaboration V6R2013xE allows an attacker to read local files on the server.

  • CVE-2022-22795MedMar 10, 2022
    risk 0.44cvss 6.8epss 0.01

    Signiant - Manager+Agents XML External Entity (XXE) - Extract internal files of the affected machine An attacker can read all the system files, the product is running with root on Linux systems and nt/authority on windows systems, which allows him to access and extract any file…

  • CVE-2020-13883MedJun 6, 2020
    risk 0.44cvss 6.7epss 0.01

    In WSO2 API Manager 3.0.0 and earlier, WSO2 API Microgateway 2.2.0, and WSO2 IS as Key Manager 5.9.0 and earlier, Management Console allows XXE during addition or update of a Lifecycle.

  • CVE-2020-1975MedFeb 12, 2020
    risk 0.44cvss 6.8epss 0.01

    Missing XML validation vulnerability in the PAN-OS web interface on Palo Alto Networks PAN-OS software allows authenticated users to inject arbitrary XML that results in privilege escalation. This issue affects PAN-OS 8.1 versions earlier than PAN-OS 8.1.12 and PAN-OS 9.0…

  • CVE-2026-33913HigMar 25, 2026
    risk 0.43cvss 7.7epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an authenticated user with access to the Carecoordination module can upload a crafted CCDA document containing `<xi:include…

  • CVE-2025-32138MedApr 4, 2025
    risk 0.43cvss 6.6epss 0.01

    Improper Restriction of XML External Entity Reference vulnerability in supsystic Easy Google Maps google-maps-easy allows XML Injection.This issue affects Easy Google Maps: from n/a through <= 1.11.18.

  • CVE-2025-31487HigApr 3, 2025
    risk 0.43cvss 7.7epss 0.00

    The XWiki JIRA extension provides various integration points between XWiki and JIRA (macros, UI, CKEditor plugin). If the JIRA macro is installed, any logged in XWiki user could edit his/her user profile wiki page and use that JIRA macro, specifying a fake JIRA URL that returns…

  • CVE-2023-28340MedApr 11, 2023
    risk 0.43cvss 6.5epss 0.03

    Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.

  • CVE-2023-27480HigMar 7, 2023
    risk 0.43cvss 7.7epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with edit rights on a document can trigger an XAR import on a forged XAR file, leading to the ability to display the content of any file on the…

  • CVE-2022-22835MedMar 10, 2022
    risk 0.43cvss 6.5epss 0.14

    An issue was discovered in OverIT Geocall before version 8.0. An authenticated user who has the Test Trasformazione XSL functionality enabled can exploit a XXE vulnerability to read arbitrary files from the filesystem.

  • CVE-2021-40439MedOct 7, 2021
    risk 0.43cvss 6.5epss 0.03

    Apache OpenOffice has a dependency on expat software. Versions prior to 2.1.0 were subject to CVE-2013-0340 a "Billion Laughs" entity expansion denial of service attack and exploit via crafted XML files. ODF files consist of a set of XML files. All versions of Apache OpenOffice…

  • CVE-2021-33813HigJun 16, 2021
    risk 0.43cvss 7.5epss 0.19

    An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.

  • CVE-2020-25649HigDec 3, 2020
    risk 0.43cvss 7.5epss 0.18

    A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.

  • CVE-2020-7032MedNov 13, 2020
    risk 0.43cvss 6.5epss 0.04

    An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. Affected versions of Avaya WebLM include: 7.0 through 7.1.3.6…

  • CVE-2020-24656MedAug 26, 2020
    risk 0.43cvss 6.5epss 0.04

    Maltego before 4.2.12 allows XXE attacks.

  • CVE-2020-13692HigJun 4, 2020
    risk 0.43cvss 7.7epss 0.04

    PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.