VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,372)

page 50 of 69
  • CVE-2025-2365MedMar 17, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability, which was classified as problematic, has been found in crmeb_java up to 1.3.4. Affected by this issue is the function webHook of the file WeChatMessageController.java. The manipulation leads to xml external entity reference. The attack may be launched remotely.…

  • CVE-2025-1225MedFeb 12, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability, which was classified as problematic, has been found in ywoa up to 2024.07.03. This issue affects the function extract of the file c-main/src/main/java/com/redmoon/weixin/aes/XMLParse.java of the component WXCallBack Interface. The manipulation leads to xml…

  • CVE-2024-49535MedDec 10, 2024
    risk 0.41cvss 6.3epss 0.00

    Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that allows an attacker to provide malicious XML input containing a reference…

  • CVE-2024-8602MedOct 14, 2024
    risk 0.41cvss —epss 0.00

    When the XML is read from the codes in the PDF and parsed using a DocumentBuilder, the default settings of the DocumentBuilder allow for an XXE (XML External Entity) attack. Further information on this can be found on the website of the Open Worldwide Application Security…

  • CVE-2024-3930MedJul 30, 2024
    risk 0.41cvss 6.3epss 0.00

    In versions of Akana API Platform prior to 2024.1.0 a flaw resulting in XML External Entity (XXE) was discovered.

  • CVE-2023-49234MedMar 29, 2024
    risk 0.41cvss 6.3epss 0.00

    An XML external entity (XXE) vulnerability was found in Stilog Visual Planning 8. It allows an authenticated attacker to access local server files and exfiltrate data to an external server.

  • CVE-2024-2826MedMar 22, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as problematic was found in lakernote EasyAdmin up to 20240315. This vulnerability affects unknown code of the file /ureport/designer/saveReportFile. The manipulation leads to xml external entity reference. The attack can be initiated remotely. The…

  • CVE-2023-30951MedAug 3, 2023
    risk 0.41cvss 6.3epss 0.00

    The Foundry Magritte plugin rest-source was found to be vulnerable to an an XML external Entity attack (XXE).

  • CVE-2023-27554MedMay 11, 2023
    risk 0.41cvss 6.3epss 0.01

    IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 249185.

  • CVE-2021-23792HigMay 6, 2022
    risk 0.41cvss 7.3epss 0.01

    The package com.twelvemonkeys.imageio:imageio-metadata before 3.7.1 are vulnerable to XML External Entity (XXE) Injection due to an insecurely initialized XML parser for reading XMP Metadata. An attacker can exploit this vulnerability if they are able to supply a file (e.g. when…

  • CVE-2021-2401MedJul 21, 2021
    risk 0.41cvss 5.3epss 0.85

    Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with…

  • CVE-2017-18438MedAug 2, 2019
    risk 0.41cvss 6.3epss 0.01

    cPanel before 64.0.21 allows demo accounts to execute code via Encoding API calls (SEC-242).

  • CVE-2018-15444MedNov 8, 2018
    risk 0.41cvss 6.3epss 0.02

    A vulnerability in the web-based user interface of Cisco Energy Management Suite Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper handling of XML…

  • CVE-2018-8533MedOct 10, 2018
    risk 0.41cvss 5.5epss 0.16

    An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious XML content containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affects SQL Server…

  • CVE-2018-8532MedOct 10, 2018
    risk 0.41cvss 5.5epss 0.16

    An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XMLA file containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affects SQL Server…

  • CVE-2018-8527MedOct 10, 2018
    risk 0.41cvss 5.5epss 0.16

    An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XEL file containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affects SQL Server…

  • CVE-2020-37192MedFeb 11, 2026
    risk 0.40cvss 6.2epss 0.00

    MSN Password Recovery 1.30 contains an XML external entity injection vulnerability that allows attackers to read local system files through crafted XML input. Attackers can exploit the 'Favorites' tab by injecting a malicious XML file that references external entities to…

  • CVE-2025-61823MedDec 10, 2025
    risk 0.40cvss 6.2epss 0.00

    ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. A high privileged attacker could exploit this vulnerability to access sensitive…

  • CVE-2021-43990MedApr 20, 2022
    risk 0.40cvss 6.1epss 0.01

    The affected product is vulnerable to a network-based attack by threat actors supplying a crafted, malicious XML payload designed to trigger an external entity reference call.

  • CVE-2019-18943MedFeb 26, 2021
    risk 0.40cvss 6.1epss 0.01

    Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to XML External Entity Processing (XXE) on certain operations.