VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,372)

page 52 of 69
  • CVE-2026-46722MedMay 19, 2026
    risk 0.38cvss —epss 0.00

    The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document placed in an indexed directory can cause local files to be read or outbound HTTP requests to be performed, with the retrieved content being written to the search…

  • CVE-2025-54992MedAug 11, 2025
    risk 0.38cvss —epss 0.00

    OpenKilda is an open-source OpenFlow controller. Prior to version 1.164.0, an XML external entity (XXE) injection vulnerability was found in OpenKilda which in combination with GHSL-2025-024 allows unauthenticated attackers to exfiltrate information from the instance where the…

  • CVE-2025-53621MedJul 15, 2025
    risk 0.38cvss 6.9epss 0.00

    DSpace open source software is a repository application which provides durable access to digital resources. Two related XML External Entity (XXE) injection possibilities impact all versions of DSpace prior to 7.6.4, 8.2, and 9.1. External entities are not disabled when parsing…

  • CVE-2025-6438MedJul 11, 2025
    risk 0.38cvss —epss 0.00

    A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause manipulation of SOAP API calls and XML external entities injection resulting in unauthorized file access when the server is accessed via the network using an application…

  • CVE-2025-49493MedJun 30, 2025
    risk 0.38cvss 5.8epss 0.02

    Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.

  • CVE-2024-56356MedDec 20, 2024
    risk 0.38cvss 5.9epss 0.00

    In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack

  • CVE-2024-31139MedMar 28, 2024
    risk 0.38cvss 5.9epss 0.00

    In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector

  • CVE-2024-28039MedMar 18, 2024
    risk 0.38cvss 5.8epss 0.01

    Improper restriction of XML external entity references vulnerability exists in FitNesse all releases, which allows a remote unauthenticated attacker to obtain sensitive information, alter data, or cause a denial-of-service (DoS) condition.

  • CVE-2023-28828MedApr 11, 2023
    risk 0.38cvss 5.9epss 0.01

    A vulnerability has been identified in Polarion ALM (All versions < V22R2). The application contains a XML External Entity Injection (XXE) vulnerability. This could allow an attacker to view files on the application server filesystem.

  • CVE-2022-3340MedNov 4, 2022
    risk 0.38cvss 5.9epss 0.01

    XML External Entity (XXE) vulnerability in Trellix IPS Manager prior to 10.1 M8 allows a remote authenticated administrator to perform XXE attack in the administrator interface part of the interface, which allows a saved XML configuration file to be imported.

  • CVE-2021-42537MedJul 27, 2022
    risk 0.38cvss 5.9epss 0.01

    VISAM VBASE version 11.6.0.6 processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

  • CVE-2022-23170MedJun 24, 2022
    risk 0.38cvss 5.9epss 0.01

    SysAid - Okta SSO integration - was found vulnerable to XML External Entity Injection vulnerability. Any SysAid environment that uses the Okta SSO integration might be vulnerable. An unauthenticated attacker could exploit the XXE vulnerability by sending a malformed POST request…

  • CVE-2018-17247MedDec 20, 2018
    risk 0.38cvss 5.9epss 0.01

    Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in Machine Learning's find_file_structure API. If a policy allowing external network access has been added to Elasticsearch's Java Security Manager then an attacker could send a specially crafted request capable…

  • CVE-2018-5434MedJun 13, 2018
    risk 0.38cvss 5.8epss 0.01

    The TIBCO Designer component of TIBCO Software Inc.'s TIBCO Runtime Agent, and TIBCO Runtime Agent for z/Linux contains vulnerabilities wherein a malicious user could perform XML external entity expansion (XXE) attacks to disclose host machine information. Affected releases are…

  • CVE-2017-6344MedFeb 27, 2017
    risk 0.38cvss 5.9epss 0.02

    XML External Entity (XXE) vulnerability in Grails PDF Plugin 0.6 allows remote attackers to read arbitrary files via a crafted XML document.

  • CVE-2016-7458MedDec 29, 2016
    risk 0.38cvss 5.8epss 0.01

    VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

  • CVE-2023-6147MedJan 9, 2024
    risk 0.37cvss 5.7epss 0.01

    Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a security flaw, which was missing a permission check while performing a connectivity check to Qualys Cloud Services. This allowed any user with login access to…

  • CVE-2023-38490MedJul 27, 2023
    risk 0.37cvss 6.8epss 0.02

    Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 only affects Kirby sites that use the `Xml` data handler (e.g. `Data::decode($string, 'xml')`) or the `Xml::parse()` method in site or plugin code. The Kirby…

  • CVE-2019-6194MedFeb 14, 2020
    risk 0.37cvss 5.7epss 0.01

    An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow information disclosure.

  • CVE-2018-0414MedOct 5, 2018
    risk 0.37cvss 5.7epss 0.02

    A vulnerability in the web-based UI of Cisco Secure Access Control Server could allow an authenticated, remote attacker to gain read access to certain information in an affected system. The vulnerability is due to improper handling of XML External Entities (XXEs) when parsing an…