VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,372)

page 53 of 69
  • CVE-2017-8710MedSep 13, 2017
    risk 0.37cvss 5.5epss 0.06

    The Microsoft Common Console Document (.msc) in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1 allows an attacker to read arbitrary files via an XML external entity (XXE) declaration, due to the way that the Microsoft Common Console Document (.msc) parses XML input…

  • CVE-2026-82525MedSep 3, 2026
    risk 0.36cvss 5.5epss 0.00

    Exterro FTK Imager before 8.3 contains an XML external entity (XXE) injection vulnerability that allows attackers to read arbitrary files from the host filesystem by embedding malicious external entity references and attacker-controlled XSLT stylesheets within a Report.xml file…

  • CVE-2026-82918MedSep 3, 2026
    risk 0.36cvss 5.5epss 0.00

    XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporation improperly restrict XML external entity references. If a user opens a specially crafted setting file, the sensitive information stored in the system where XG VisionTerminal or XG-X VisionTerminal is…

  • CVE-2026-75058MedAug 17, 2026
    risk 0.36cvss 5.5epss 0.00

    In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers

  • CVE-2026-75055MedAug 17, 2026
    risk 0.36cvss 5.5epss 0.00

    In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE

  • CVE-2026-14304MedAug 5, 2026
    risk 0.36cvss 5.5epss 0.00

    In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. If this…

  • CVE-2026-6807MedApr 28, 2026
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in GRASSMARLIN v3.2.1 allows crafted session data to trigger improper handling of XML input, which may result in unintended exposure of sensitive information. The flaw stems from insufficient hardening of the XML parsing process.

  • CVE-2025-15251MedDec 30, 2025
    risk 0.36cvss 5.6epss 0.00

    A vulnerability was detected in beecue FastBee up to 2.1. Impacted is the function getRootElement of the file springboot/fastbee-server/sip-server/src/main/java/com/fastbee/sip/handler/req/ReqAbstractHandler.java of the component SIP Message Handler. The manipulation results in…

  • CVE-2025-57704MedAug 26, 2025
    risk 0.36cvss 5.5epss 0.00

    Delta Electronics EIP Builder version 1.11 is vulnerable to a File Parsing XML External Entity Processing Information Disclosure Vulnerability.

  • CVE-2025-26484MedAug 14, 2025
    risk 0.36cvss 5.5epss 0.00

    Dell CloudLink, versions 8.0 through 8.1.1, contains an Improper Restriction of XML External Entity Reference vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.

  • CVE-2025-40584MedAug 12, 2025
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been identified in SIMOTION SCOUT TIA V5.4 (All versions), SIMOTION SCOUT TIA V5.5 (All versions), SIMOTION SCOUT TIA V5.6 (All versions < V5.6 SP1 HF7), SIMOTION SCOUT TIA V5.7 (All versions < V5.7 SP1 HF1), SIMOTION SCOUT V5.4 (All versions), SIMOTION SCOUT…

  • CVE-2024-12298MedJan 14, 2025
    risk 0.36cvss 5.5epss 0.00

    We found a vulnerability Improper Restriction of XML External Entity Reference (CWE-611) in NB-series NX-Designer. Attackers may be able to abuse this vulnerability to disclose confidential data on a computer.

  • CVE-2024-49704MedDec 10, 2024
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been identified in COMOS V10.3 (All versions < V10.3.3.5.8), COMOS V10.4.0 (All versions), COMOS V10.4.1 (All versions), COMOS V10.4.2 (All versions), COMOS V10.4.3 (All versions < V10.4.3.0.47), COMOS V10.4.4 (All versions < V10.4.4.2), COMOS V10.4.4.1 (All…

  • CVE-2024-20531MedNov 6, 2024
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device and conduct a server-side request forgery (SSRF) attack through an affected device. To exploit this…

  • CVE-2024-45086MedNov 4, 2024
    risk 0.36cvss 5.5epss 0.00

    IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.

  • CVE-2024-45072MedOct 16, 2024
    risk 0.36cvss 5.5epss 0.00

    IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.

  • CVE-2024-25971MedMar 28, 2024
    risk 0.36cvss 5.5epss 0.01

    Dell PowerProtect Data Manager, version 19.15, contains an XML External Entity Injection vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to information disclosure, denial-of-service.

  • CVE-2023-25926MedFeb 29, 2024
    risk 0.36cvss 5.5epss 0.01

    IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. …

  • CVE-2024-1167MedFeb 1, 2024
    risk 0.36cvss 5.5epss 0.01

    When SEW-EURODRIVE MOVITOOLS MotionStudio processes XML information unrestricted file access can occur.

  • CVE-2024-22380MedJan 24, 2024
    risk 0.36cvss 5.5epss 0.00

    Electronic Delivery Check System (Ministry of Agriculture, Forestry and Fisheries The Agriculture and Rural Development Project Version) March, Heisei 31 era edition Ver.14.0.001.002 and earlier improperly restricts XML external entity references (XXE). By processing a specially…