CWE-611— Improper Restriction of XML External Entity Reference (XXE)
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.— MITRE CWE catalog
1,275 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-611page 10 of 26
- CVE-2019-19031HIGHCVSS 8.1EG 8.12019-12-30
Easy XML Editor through v1.7.8 is affected by: XML External Entity Injection. The impact is: Arbitrary File Read and DoS by consuming resources. The component is: XML Parsing. The attack vector is: Specially crafted XML payload.
- CVE-2019-19032HIGHCVSS 8.1EG 8.12019-12-30
XMLBlueprint through 16.191112 is affected by XML External Entity Injection. The impact is: Arbitrary File Read when an XML File is validated. The component is: XML Validate function. The attack vector is: Specially crafted XML payload.
- CVE-2019-19702HIGHCVSS 7.5EG 7.52019-12-10
The modoboa-dmarc plugin 1.1.0 for Modoboa is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this to perform a denial of service against the DMARC reporting functionali…
- CVE-2019-19998HIGHCVSS 7.5EG 7.52019-12-26
Xiuno BBS 4.0 allows XXE via plugin/xn_wechat_public/route/token.php.
- CVE-2019-20153MEDIUMCVSS 4.9EG 4.92020-01-05
An issue was discovered in Determine (formerly Selectica) Contract Lifecycle Management (CLM) in v5.4. An XML external entity (XXE) vulnerability in the upload definition feature in definition_upload_attach.jsp allows authenticated remote …
- CVE-2019-20191HIGHCVSS 7.5EG 7.52020-03-16
Oxygen XML Editor 21.1.1 allows XXE to read any file.
- CVE-2019-20627CRITICALCVSS 9.8EG 9.82020-03-23
AutoUpdater.cs in AutoUpdater.NET before 1.5.8 allows XXE.
- CVE-2019-25253HIGHCVSS 7.5EG 7.52025-12-24
KYOCERA Net Admin 3.4.0906 contains an XML External Entity (XXE) injection vulnerability in the Multi-Set Template Editor that allows unauthenticated attackers to read arbitrary system files. Attackers can craft a malicious XML file with e…
- CVE-2019-2861MEDIUMCVSS 4.2EG 4.22019-07-23
Vulnerability in the Oracle Hyperion Planning component of Oracle Hyperion (subcomponent: Security). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access…
- CVE-2019-3481HIGHCVSS 7.1EG 7.12019-03-25
Mitigates a XML External Entity Parsing issue in ArcSight Logger versions prior to 6.7.
- CVE-2019-3722HIGHCVSS 7.5EG 7.52019-06-06
Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain an XML external entity (XXE) injection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to …
- CVE-2019-3752HIGHCVSS 8.2EG 8.22021-07-16
Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2 and 19.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1, 2.2, 2.3 and 2.4. contain an XML External Entity(XXE) Injection vulnerability. A remote unauthen…
- CVE-2019-3768MEDIUMCVSS 6.5EG 6.52020-01-03
RSA Authentication Manager versions prior to 8.4 P7 contain an XML Entity Injection Vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to cause information disclosure of local system files by …
- CVE-2019-3772CRITICALCVSS 9.8EG 9.82019-01-18
Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted s…
- CVE-2019-3773CRITICALCVSS 9.8EG 9.82019-01-18
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
- CVE-2019-3774CRITICALCVSS 9.8EG 9.82019-01-18
Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
- CVE-2019-4043HIGHCVSS 7.1EG 7.12019-04-02
IBM Sterling B2B Integrator Standard Edition 5.2.0 snf 6.0.0.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or c…
- CVE-2019-4062HIGHCVSS 7.1EG 7.12019-07-30
IBM i2 Intelligent Analyis Platform 9.0.0 through 9.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume …
- CVE-2019-4208HIGHCVSS 7.1EG 7.12019-05-07
IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory …
- CVE-2019-4340HIGHCVSS 8.2EG 8.22019-08-20
IBM Security Guardium Big Data Intelligence 4.0 (SonarG) is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume…
- CVE-2019-4391HIGHCVSS 8.2EG 8.22020-04-07
HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data
- CVE-2019-4419HIGHCVSS 8.2EG 8.22019-08-20
IBM Intelligent Operations Center V5.1.0 through V5.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume …
- CVE-2019-4424HIGHCVSS 8.2EG 8.22019-08-20
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, and 19.0.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sen…
- CVE-2019-4433HIGHCVSS 8.2EG 8.22019-08-20
IBM InfoSphere Global Name Management 5.0 and 6.0 and IBM InfoSphere Identity Insight 8.1 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability t…
- CVE-2019-4456HIGHCVSS 7.1EG 7.12019-07-30
IBM Daeja ViewONE Professional, Standard & Virtual 5.0.5 and 5.0.6 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information …
- CVE-2019-4513HIGHCVSS 8.2EG 8.22019-08-26
IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or …
- CVE-2019-4707HIGHCVSS 7.1EG 7.12020-01-28
IBM Security Access Manager Appliance 9.0.7.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory res…
- CVE-2019-4730HIGHCVSS 7.1EG 7.12021-06-01
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM…
- CVE-2019-5312CRITICALCVSS 9.8EG 9.82019-01-04
An issue was discovered in weixin-java-tools v3.3.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file. NOTE: this issue exists because of an incomplete fix for CVE-2018-20318.
- CVE-2019-5748CRITICALCVSS 9.8EG 9.82019-01-09
In Traccar Server version 4.2, protocol/SpotProtocolDecoder.java might allow XXE attacks.
- CVE-2019-5918CRITICALCVSS 9.1EG 9.12019-03-12
Nablarch 5 (5, and 5u1 to 5u13) allows remote attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.
- CVE-2019-6179HIGHCVSS 7.5EG 7.52019-09-03
An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) prior to version 2.5.0 , Lenovo XClarity Integrator (LXCI) for Microsoft System Center prior to version 7.7.0, and Lenovo XClarity I…
- CVE-2019-6194MEDIUMCVSS 5.7EG 5.72020-02-14
An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow information disclosure.
- CVE-2019-7442CRITICALCVSS 9.8EG 9.82019-05-08
An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remote attackers to read arbitrary files or potentially bypass authentication via a crafted DTD in the S…
- CVE-2019-7722HIGHCVSS 8.1EG 8.12019-02-11
PMD 5.8.1 and earlier processes XML external entities in ruleset files it parses as part of the analysis process, allowing attackers tampering it (either by direct modification or MITM attacks when using remote rulesets) to perform informa…
- CVE-2019-7847HIGHCVSS 7.5EG 7.52019-07-18
Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Improper Restriction of XML External Entity Reference ('XXE') vulnerability. Successful exploitation could lead to Arbitrary read access to the file system in the con…
- CVE-2019-8082HIGHCVSS 7.5EG 7.52019-10-25
Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
- CVE-2019-8086HIGHCVSS 7.5EG 7.52019-10-25
Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
- CVE-2019-8087HIGHCVSS 7.5EG 7.52019-10-25
Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
- CVE-2019-8126MEDIUMCVSS 4.9EG 4.92019-11-05
An XML entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can craft document type definition for an XML representing XML layout. The crafted document ty…
- CVE-2019-8997MEDIUMCVSS 5.9EG 5.92019-03-21
An XML External Entity Injection (XXE) vulnerability in the Management System (console) of BlackBerry AtHoc versions earlier than 7.6 HF-567 could allow an attacker to potentially read arbitrary local files from the application server or m…
- CVE-2019-8999HIGHCVSS 7.5EG 7.52019-04-18
An XML External Entity vulnerability in the UEM Core of BlackBerry UEM version(s) earlier than 12.10.1a could allow an attacker to potentially gain read access to files on any system reachable by the UEM service account.
- CVE-2019-9488MEDIUMCVSS 4.9EG 4.92019-09-11
Trend Micro Deep Security Manager (10.x, 11.x) and Vulnerability Protection (2.0) are vulnerable to a XML External Entity Attack. However, for the attack to be possible, the attacker must have root/admin access to a protected host which is…
- CVE-2019-9658MEDIUMCVSS 5.3EG 5.32019-03-11
Checkstyle before 8.18 loads external DTDs by default.
- CVE-2019-9670CRITICALCVSS 9.8EG 9.8⚠ KEV2019-05-29
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.
- CVE-2019-9757HIGHCVSS 7.5EG 7.72019-10-29
An issue was discovered in LabKey Server 19.1.0. Sending an SVG containing an XXE payload to the endpoint visualization-exportImage.view or visualization-exportPDF.view allows local files to be read.
- CVE-2019-9761HIGHCVSS 7.5EG 7.52019-03-14
An XXE issue was discovered in PHPSHE 1.7, which can be used to read any file in the system or scan the internal network without authentication. This occurs because of the call to wechat_getxml in include/plugin/payment/wechat/notify_url.p…
- CVE-2019-9843HIGHCVSS 7.5EG 7.52019-06-28
In DiffPlug Spotless before 1.20.0 (library and Maven plugin) and before 3.20.0 (Gradle plugin), the XML parser would resolve external entities over both HTTP and HTTPS and didn't respect the resolveExternalEntities setting. For example, t…
- CVE-2020-10629HIGHCVSS 7.5EG 7.52020-04-09
WebAccess/NMS (versions prior to 3.0.2) does not sanitize XML input. Specially crafted XML input could allow an attacker to read sensitive files.
- CVE-2020-10683CRITICALCVSS 9.8EG 9.82020-05-01
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavi…
Map vulnerabilities like CWE-611 to your infrastructure
EchelonGraph correlates every CVE — across CWE-611 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →