VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,372)

page 51 of 69
  • CVE-2018-17186HigNov 6, 2018
    risk 0.40cvss 7.2epss 0.02

    An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.

  • CVE-2026-42212HigMay 8, 2026
    risk 0.39cvss —epss 0.00

    SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, Opening a .gpp file in the SolidCAM Postprocessor IDE extension causes the language server to parse a companion .vmid file from the…

  • CVE-2015-3542higNov 7, 2024
    risk 0.39cvss —epss 0.00

    PHPExcel XXE Vulnerability

  • CVE-2023-20030MedApr 5, 2023
    risk 0.39cvss 6.0epss 0.01

    A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information, conduct a server-side request forgery (SSRF) attack through an affected device, or negatively impact the…

  • CVE-2022-43473MedMar 30, 2023
    risk 0.39cvss 5.8epss 0.20

    A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability.

  • CVE-2022-0198HigJan 13, 2022
    risk 0.39cvss 7.1epss 0.01

    corenlp is vulnerable to Improper Restriction of XML External Entity Reference

  • CVE-2021-43577HigNov 12, 2021
    risk 0.39cvss 7.1epss 0.01

    Jenkins OWASP Dependency-Check Plugin 5.1.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2021-21680HigAug 31, 2021
    risk 0.39cvss 7.1epss 0.01

    Jenkins Nested View Plugin 1.20 and earlier does not configure its XML transformer to prevent XML external entity (XXE) attacks.

  • CVE-2021-21656HigMay 11, 2021
    risk 0.39cvss 7.1epss 0.02

    Jenkins Xcode integration Plugin 2.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2020-2144HigMar 9, 2020
    risk 0.39cvss 7.1epss 0.01

    Jenkins Rundeck Plugin 3.6.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2020-2138HigMar 9, 2020
    risk 0.39cvss 7.1epss 0.01

    Jenkins Cobertura Plugin 1.15 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2015-8549HigJan 15, 2020
    risk 0.39cvss 7.1epss 0.02

    XML external entity (XXE) vulnerability in PyAMF before 0.8.0 allows remote attackers to cause a denial of service or read arbitrary files via a crafted Action Message Format (AMF) payload.

  • CVE-2019-0284MedApr 10, 2019
    risk 0.39cvss 6.0epss 0.00

    SLD Registration in SAP HANA (fixed in versions 1.0, 2.0) does not sufficiently validate an XML document accepted from an untrusted source. The attacker can call SLDREG with an XML file containing a reference to an XML External Entity (XXE). This can cause SLDREG to, for…

  • CVE-2019-8997MedMar 21, 2019
    risk 0.39cvss 5.9epss 0.02

    An XML External Entity Injection (XXE) vulnerability in the Management System (console) of BlackBerry AtHoc versions earlier than 7.6 HF-567 could allow an attacker to potentially read arbitrary local files from the application server or make requests on the network by entering…

  • CVE-2018-10832MedMay 11, 2018
    risk 0.39cvss 5.5epss 0.06

    ModbusPal 1.6b is vulnerable to an XML External Entity (XXE) attack. Projects are saved as .xmpp files and automations can be exported as .xmpa files, both XML-based, which are vulnerable to XXE injection. Sending a crafted .xmpp or .xmpa file to a user, when opened/imported in…

  • CVE-2017-8918MedSep 12, 2017
    risk 0.39cvss 5.5epss 0.02

    XXE in Dive Assistant - Template Builder in Blackwave Dive Assistant - Desktop Edition 8.0 allows attackers to remotely view local files via a crafted template.xml file.

  • CVE-2017-9095MedSep 8, 2017
    risk 0.39cvss 5.5epss 0.04

    XXE in Diving Log 6.0 allows attackers to remotely view local files through a crafted dive.xml file that is mishandled during a Subsurface import.

  • CVE-2016-6805MedApr 7, 2017
    risk 0.39cvss 5.9epss 0.02

    Apache Ignite before 1.9 allows man-in-the-middle attackers to read arbitrary files via XXE in modified update-notifier documents.

  • CVE-2011-4107MedNov 17, 2011
    risk 0.39cvss 6.5epss 0.13

    The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external…

  • CVE-2026-54640higJul 6, 2026
    risk 0.38cvss —epss —

    ### Summary The fix for CVE-2026-40882 addressed only the Velbus asset import handler. The KNX asset import handler (`KNXProtocol`) processes user-uploaded ETS project ZIP files through Saxon XSLT and `XMLInputFactory.newInstance()` with no XXE protection, allowing any…