VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,331)

page 9 of 67
  • CVE-2026-4374CriApr 1, 2026
    risk 0.59cvss 9.1epss 0.00

    Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Cloud Discovery Service, Recording Service, Routing Service, Queueing Service, Observability Collector) allows Serialized Data External Linking, Data Serialization External Entities…

  • CVE-2025-48006CriSep 29, 2025
    risk 0.59cvss 9.1epss 0.01

    Improper restriction of XML external entity reference issue exists in DataSpider Servista 4.4 and earlier. If a specially crafted request is processed, arbitrary files on the file system where the server application for the product is installed may be read, or a…

  • CVE-2025-10183CriSep 9, 2025
    risk 0.59cvss 9.1epss 0.00

    A blind XML External Entity (XXE) injection in the OpenMessaging webservice in TecCom TecConnect 4.1 allows an unauthenticated attacker to exfiltrate arbitrary files to an attacker-controlled server. TecConnect 4.1 is considered end-of-life as of December 2023. Users are advised…

  • CVE-2025-31039CriJun 9, 2025
    risk 0.59cvss 9.1epss 0.00

    Improper Restriction of XML External Entity Reference vulnerability in pixelgrade Category Icon category-icon allows XML Entity Linking.This issue affects Category Icon: from n/a through <= 1.0.3.

  • CVE-2025-2905CriMay 5, 2025
    risk 0.59cvss 9.1epss 0.01

    Due to the improper configuration of XML parser, user-supplied XML is parsed without applying sufficient restrictions, enabling XML External Entity (XXE) resolution in multiple WSO2 Products. A successful XXE attack could allow a remote, unauthenticated attacker to: * Read…

  • CVE-2024-37388CriJun 7, 2024
    risk 0.59cvss 9.1epss 0.01

    An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of lxml before v4.9.1 allows attackers to access sensitive information or cause a Denial of Service (DoS) via crafted XML input.

  • CVE-2023-37364CriAug 3, 2023
    risk 0.59cvss 9.1epss 0.01

    In WS-Inc J WBEM Server 4.7.4 before 4.7.5, the CIM-XML protocol adapter does not disable entity resolution. This allows context-dependent attackers to read arbitrary files or cause a denial of service, a similar issue to CVE-2013-4152.

  • CVE-2023-24470CriJun 13, 2023
    risk 0.59cvss 9.1epss 0.01

    Potential XML External Entity Injection in ArcSight Logger versions prior to 7.3.0.

  • CVE-2022-40747CriNov 3, 2022
    risk 0.59cvss 9.1epss 0.01

    "IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 236584."

  • CVE-2022-41241CriSep 21, 2022
    risk 0.59cvss 9.1epss 0.01

    Jenkins RQM Plugin 2.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-22489CriAug 19, 2022
    risk 0.59cvss 9.1epss 0.01

    IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 226339.

  • CVE-2022-31775CriAug 1, 2022
    risk 0.59cvss 9.1epss 0.01

    IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose…

  • CVE-2022-25312CriMar 5, 2022
    risk 0.59cvss 9.1epss 0.03

    An XML external entity (XXE) injection vulnerability was discovered in the Any23 RDFa XSLTStylesheet extractor and is known to affect Any23 versions < 2.7. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with…

  • CVE-2021-44557CriDec 8, 2021
    risk 0.59cvss 9.1epss 0.01

    National Library of the Netherlands multiNER <= c0440948057afc6e3d6b4903a7c05e666b94a3bc is affected by an XML External Entity (XXE) vulnerability in multiNER/ner.py. Since XML parsing resolves external entities, a malicious XML stream could leak internal files and/or cause a…

  • CVE-2020-26705CriOct 31, 2021
    risk 0.59cvss 9.1epss 0.01

    The parseXML function in Easy-XML 0.5.0 was discovered to have a XML External Entity (XXE) vulnerability which allows for an attacker to expose sensitive data or perform a denial of service (DOS) via a crafted external entity entered into the XML content as input.

  • CVE-2020-25912CriOct 31, 2021
    risk 0.59cvss 9.1epss 0.01

    A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).

  • CVE-2021-38555CriSep 11, 2021
    risk 0.59cvss 9.1epss 0.03

    An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to affect Any23 versions < 2.5. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an…

  • CVE-2021-34823CriAug 13, 2021
    risk 0.59cvss 9.1epss 0.02

    The ON24 ScreenShare (aka DesktopScreenShare.app) plugin before 2.0 for macOS allows remote file access via its built-in HTTP server. This allows unauthenticated remote users to retrieve files accessible to the logged-on macOS user. When a remote user sends a crafted HTTP…

  • CVE-2021-27741CriAug 13, 2021
    risk 0.59cvss 9.1epss 0.01

    " Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection"

  • CVE-2021-20399CriJul 27, 2021
    risk 0.59cvss 9.1epss 0.02

    IBM Qradar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID:…