VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,331)

page 42 of 67
  • CVE-2025-52162MedJul 18, 2025
    risk 0.42cvss 6.5epss 0.00

    agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to contain an XML External Entity (XXE) via the RSSReader endpoint. This vulnerability allows attackers to access sensitive data via providing a crafted XML input.

  • CVE-2025-52888HigJun 24, 2025
    risk 0.42cvss 7.5epss 0.00

    Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. A critical XML External Entity (XXE) vulnerability exists in the xunit-xml-plugin used by Allure 2 prior to version 2.34.1. The plugin fails to securely configure the XML parser…

  • CVE-2024-51445MedMay 13, 2025
    risk 0.42cvss 6.5epss 0.01

    A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The affected application contains a XML External Entity Injection (XXE) vulnerability in the docx import feature. This could allow an authenticated remote attacker to…

  • CVE-2025-34490MedApr 28, 2025
    risk 0.42cvss 6.5epss 0.01

    GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted HTTP requests to read arbitrary system files.

  • CVE-2025-31497HigApr 15, 2025
    risk 0.42cvss 7.5epss 0.00

    TEIGarage is a webservice and RESTful service to transform, convert and validate various formats, focussing on the TEI format. The Document Conversion Service contains a critical XML External Entity (XXE) Injection vulnerability in its document conversion functionality. The…

  • CVE-2025-1781MedMar 28, 2025
    risk 0.42cvss 6.5epss 0.00

    There is a XXE in W3CSS Validator versions before cssval-20250226 that allows an attacker to use specially-crafted XML objects to coerce server-side request forgery (SSRF).  This could be exploited to read arbitrary local files if an attacker has access to exception messages.

  • CVE-2025-23195HigJan 21, 2025
    risk 0.42cvss 7.5epss 0.01

    An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie project, allowing an attacker to inject malicious XML entities. This vulnerability occurs due to insecure parsing of XML input using the `DocumentBuilderFactory` class without disabling external entity …

  • CVE-2024-49064MedDec 12, 2024
    risk 0.42cvss 6.5epss 0.03

    Microsoft SharePoint Information Disclosure Vulnerability

  • CVE-2024-50848MedNov 18, 2024
    risk 0.42cvss 6.5epss 0.01

    An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute arbitrary commands via supplying a crafted .tmx file.

  • CVE-2020-26066MedNov 18, 2024
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper handling of XML External Entity (XXE)…

  • CVE-2021-1483MedNov 15, 2024
    risk 0.42cvss 6.4epss 0.01

    A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. This vulnerability is due to improper handling of XML External Entity (XXE)…

  • CVE-2024-5919MedNov 14, 2024
    risk 0.42cvss 6.5epss 0.00

    A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate arbitrary files from firewalls to an attacker controlled server. This attack requires network access to the firewall management…

  • CVE-2024-28168HigOct 9, 2024
    risk 0.42cvss 7.5epss 0.01

    Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: 2.9. Users are recommended to upgrade to version 2.10, which fixes the issue.

  • CVE-2024-45293HigOct 7, 2024
    risk 0.42cvss 7.5epss 0.03

    PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The security scanner responsible for preventing XXE attacks in the XLSX reader can be bypassed by slightly modifying the XML structure, utilizing white-spaces. On servers that allow users to upload…

  • CVE-2024-5625MedJul 18, 2024
    risk 0.42cvss 6.5epss 0.00

    Improper Restriction of XML External Entity Reference vulnerability in PruvaSoft Informatics Apinizer Management Console allows Data Serialization External Entities Blowup. This issue affects Apinizer Management Console: before 2024.05.1.

  • CVE-2024-38374HigJun 28, 2024
    risk 0.42cvss 7.5epss 0.01

    The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, validating, and parsing SBOMs. Before deserializing CycloneDX Bill of Materials in XML format, _cyclonedx-core-java_ leverages XPath expressions to determine the…

  • CVE-2021-47621HigJun 21, 2024
    risk 0.42cvss 7.5epss 0.01

    ClassGraph before 4.8.112 was not resistant to XML eXternal Entity (XXE) attacks.

  • CVE-2024-4357MedMay 15, 2024
    risk 0.42cvss 6.5epss 0.01

    An information disclosure vulnerability exists in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, allows low-privilege attacker to read systems file via XML External Entity Processing.

  • CVE-2023-51605MedMay 3, 2024
    risk 0.42cvss 6.5epss 0.01

    Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Honeywell Saia PG5 Controls Suite. User interaction is required to…

  • CVE-2023-51604MedMay 3, 2024
    risk 0.42cvss 6.5epss 0.01

    Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Honeywell Saia PG5 Controls Suite. User interaction is required to…