CWE-611
Improper Restriction of XML External Entity Reference
Description
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-221
CVEs mapped to this weakness (1,331)
page 50 of 67| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-2138 | Hig | 0.39 | 7.1 | 0.01 | Mar 9, 2020 | Jenkins Cobertura Plugin 1.15 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | ||
| CVE-2015-8549 | Hig | 0.39 | 7.1 | 0.02 | Jan 15, 2020 | XML external entity (XXE) vulnerability in PyAMF before 0.8.0 allows remote attackers to cause a denial of service or read arbitrary files via a crafted Action Message Format (AMF) payload. | ||
| CVE-2019-0284 | Med | 0.39 | 6.0 | 0.00 | Apr 10, 2019 | SLD Registration in SAP HANA (fixed in versions 1.0, 2.0) does not sufficiently validate an XML document accepted from an untrusted source. The attacker can call SLDREG with an XML file containing a reference to an XML External Entity (XXE). This can cause SLDREG to, for… | ||
| CVE-2019-8997 | Med | 0.39 | 5.9 | 0.02 | Mar 21, 2019 | An XML External Entity Injection (XXE) vulnerability in the Management System (console) of BlackBerry AtHoc versions earlier than 7.6 HF-567 could allow an attacker to potentially read arbitrary local files from the application server or make requests on the network by entering… | ||
| CVE-2018-10832 | Med | 0.39 | 5.5 | 0.06 | May 11, 2018 | ModbusPal 1.6b is vulnerable to an XML External Entity (XXE) attack. Projects are saved as .xmpp files and automations can be exported as .xmpa files, both XML-based, which are vulnerable to XXE injection. Sending a crafted .xmpp or .xmpa file to a user, when opened/imported in… | ||
| CVE-2017-8918 | Med | 0.39 | 5.5 | 0.02 | Sep 12, 2017 | XXE in Dive Assistant - Template Builder in Blackwave Dive Assistant - Desktop Edition 8.0 allows attackers to remotely view local files via a crafted template.xml file. | ||
| CVE-2017-9095 | Med | 0.39 | 5.5 | 0.04 | Sep 8, 2017 | XXE in Diving Log 6.0 allows attackers to remotely view local files through a crafted dive.xml file that is mishandled during a Subsurface import. | ||
| CVE-2016-6805 | Med | 0.39 | 5.9 | 0.02 | Apr 7, 2017 | Apache Ignite before 1.9 allows man-in-the-middle attackers to read arbitrary files via XXE in modified update-notifier documents. | ||
| CVE-2011-4107 | Med | 0.39 | 6.5 | 0.13 | Nov 17, 2011 | The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external… | ||
| CVE-2026-54640 | hig | 0.38 | — | — | Jul 6, 2026 | ### Summary The fix for CVE-2026-40882 addressed only the Velbus asset import handler. The KNX asset import handler (`KNXProtocol`) processes user-uploaded ETS project ZIP files through Saxon XSLT and `XMLInputFactory.newInstance()` with no XXE protection, allowing any… | ||
| CVE-2026-46722 | Med | 0.38 | — | 0.00 | May 19, 2026 | The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document placed in an indexed directory can cause local files to be read or outbound HTTP requests to be performed, with the retrieved content being written to the search… | ||
| CVE-2025-54992 | Med | 0.38 | — | 0.00 | Aug 11, 2025 | OpenKilda is an open-source OpenFlow controller. Prior to version 1.164.0, an XML external entity (XXE) injection vulnerability was found in OpenKilda which in combination with GHSL-2025-024 allows unauthenticated attackers to exfiltrate information from the instance where the… | ||
| CVE-2025-53621 | Med | 0.38 | 6.9 | 0.00 | Jul 15, 2025 | DSpace open source software is a repository application which provides durable access to digital resources. Two related XML External Entity (XXE) injection possibilities impact all versions of DSpace prior to 7.6.4, 8.2, and 9.1. External entities are not disabled when parsing… | ||
| CVE-2025-6438 | Med | 0.38 | — | 0.00 | Jul 11, 2025 | A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause manipulation of SOAP API calls and XML external entities injection resulting in unauthorized file access when the server is accessed via the network using an application… | ||
| CVE-2025-49493 | Med | 0.38 | 5.8 | 0.03 | Jun 30, 2025 | Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection. | ||
| CVE-2024-56356 | Med | 0.38 | 5.9 | 0.00 | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack | ||
| CVE-2024-31139 | Med | 0.38 | 5.9 | 0.00 | Mar 28, 2024 | In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector | ||
| CVE-2024-28039 | Med | 0.38 | 5.8 | 0.01 | Mar 18, 2024 | Improper restriction of XML external entity references vulnerability exists in FitNesse all releases, which allows a remote unauthenticated attacker to obtain sensitive information, alter data, or cause a denial-of-service (DoS) condition. | ||
| CVE-2023-28828 | Med | 0.38 | 5.9 | 0.01 | Apr 11, 2023 | A vulnerability has been identified in Polarion ALM (All versions < V22R2). The application contains a XML External Entity Injection (XXE) vulnerability. This could allow an attacker to view files on the application server filesystem. | ||
| CVE-2022-3340 | Med | 0.38 | 5.9 | 0.01 | Nov 4, 2022 | XML External Entity (XXE) vulnerability in Trellix IPS Manager prior to 10.1 M8 allows a remote authenticated administrator to perform XXE attack in the administrator interface part of the interface, which allows a saved XML configuration file to be imported. |
- risk 0.39cvss 7.1epss 0.01
Jenkins Cobertura Plugin 1.15 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- risk 0.39cvss 7.1epss 0.02
XML external entity (XXE) vulnerability in PyAMF before 0.8.0 allows remote attackers to cause a denial of service or read arbitrary files via a crafted Action Message Format (AMF) payload.
- risk 0.39cvss 6.0epss 0.00
SLD Registration in SAP HANA (fixed in versions 1.0, 2.0) does not sufficiently validate an XML document accepted from an untrusted source. The attacker can call SLDREG with an XML file containing a reference to an XML External Entity (XXE). This can cause SLDREG to, for…
- risk 0.39cvss 5.9epss 0.02
An XML External Entity Injection (XXE) vulnerability in the Management System (console) of BlackBerry AtHoc versions earlier than 7.6 HF-567 could allow an attacker to potentially read arbitrary local files from the application server or make requests on the network by entering…
- risk 0.39cvss 5.5epss 0.06
ModbusPal 1.6b is vulnerable to an XML External Entity (XXE) attack. Projects are saved as .xmpp files and automations can be exported as .xmpa files, both XML-based, which are vulnerable to XXE injection. Sending a crafted .xmpp or .xmpa file to a user, when opened/imported in…
- risk 0.39cvss 5.5epss 0.02
XXE in Dive Assistant - Template Builder in Blackwave Dive Assistant - Desktop Edition 8.0 allows attackers to remotely view local files via a crafted template.xml file.
- risk 0.39cvss 5.5epss 0.04
XXE in Diving Log 6.0 allows attackers to remotely view local files through a crafted dive.xml file that is mishandled during a Subsurface import.
- risk 0.39cvss 5.9epss 0.02
Apache Ignite before 1.9 allows man-in-the-middle attackers to read arbitrary files via XXE in modified update-notifier documents.
- risk 0.39cvss 6.5epss 0.13
The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external…
- risk 0.38cvss —epss —
### Summary The fix for CVE-2026-40882 addressed only the Velbus asset import handler. The KNX asset import handler (`KNXProtocol`) processes user-uploaded ETS project ZIP files through Saxon XSLT and `XMLInputFactory.newInstance()` with no XXE protection, allowing any…
- risk 0.38cvss —epss 0.00
The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document placed in an indexed directory can cause local files to be read or outbound HTTP requests to be performed, with the retrieved content being written to the search…
- risk 0.38cvss —epss 0.00
OpenKilda is an open-source OpenFlow controller. Prior to version 1.164.0, an XML external entity (XXE) injection vulnerability was found in OpenKilda which in combination with GHSL-2025-024 allows unauthenticated attackers to exfiltrate information from the instance where the…
- risk 0.38cvss 6.9epss 0.00
DSpace open source software is a repository application which provides durable access to digital resources. Two related XML External Entity (XXE) injection possibilities impact all versions of DSpace prior to 7.6.4, 8.2, and 9.1. External entities are not disabled when parsing…
- risk 0.38cvss —epss 0.00
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause manipulation of SOAP API calls and XML external entities injection resulting in unauthorized file access when the server is accessed via the network using an application…
- risk 0.38cvss 5.8epss 0.03
Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.
- risk 0.38cvss 5.9epss 0.00
In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack
- risk 0.38cvss 5.9epss 0.00
In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector
- risk 0.38cvss 5.8epss 0.01
Improper restriction of XML external entity references vulnerability exists in FitNesse all releases, which allows a remote unauthenticated attacker to obtain sensitive information, alter data, or cause a denial-of-service (DoS) condition.
- risk 0.38cvss 5.9epss 0.01
A vulnerability has been identified in Polarion ALM (All versions < V22R2). The application contains a XML External Entity Injection (XXE) vulnerability. This could allow an attacker to view files on the application server filesystem.
- risk 0.38cvss 5.9epss 0.01
XML External Entity (XXE) vulnerability in Trellix IPS Manager prior to 10.1 M8 allows a remote authenticated administrator to perform XXE attack in the administrator interface part of the interface, which allows a saved XML configuration file to be imported.