CWE-611— Improper Restriction of XML External Entity Reference (XXE)
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.— MITRE CWE catalog
1,275 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-611page 12 of 26
- CVE-2020-24379CRITICALCVSS 9.8EG 9.82020-09-09
WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.
- CVE-2020-24454HIGHCVSS 7.5EG 7.52020-11-12
Improper Restriction of XML External Entity Reference in subsystem forIntel(R) Quartus(R) Prime Pro Edition before version 20.3 and Intel(R) Quartus(R) Prime Standard Edition before version 20.2 may allow unauthenticated user to potentiall…
- CVE-2020-24589CRITICALCVSS 9.1EG 9.12020-08-21
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.
- CVE-2020-24591MEDIUMCVSS 6.5EG 6.52020-08-21
The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates. This affects API Manager through 3.0.0, API Manager Analytics 2.2.0 and 2.5.0, API Microgateway 2.2.0, Enterprise Integrator 6.2.0 and 6.3.0, …
- CVE-2020-24656MEDIUMCVSS 6.5EG 6.52020-08-26
Maltego before 4.2.12 allows XXE attacks.
- CVE-2020-25020CRITICALCVSS 9.8EG 9.82020-08-29
MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components.
- CVE-2020-25186HIGHCVSS 7.5EG 7.52020-10-22
An XXE vulnerability exists within LeviStudioU Release Build 2019-09-21 and prior when processing parameter entities, which may allow file disclosure.
- CVE-2020-25215CRITICALCVSS 9.8EG 9.82020-09-17
yWorks yEd Desktop before 3.20.1 allows XXE attacks via an XML or GraphML document.
- CVE-2020-25257CRITICALCVSS 9.8EG 9.82020-09-11
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows XXE attacks for read/write access to arbitrary files.
- CVE-2020-25649HIGHCVSS 7.5EG 7.52020-12-03
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
- CVE-2020-25750HIGHCVSS 7.5EG 7.52020-09-18
An issue was discovered in DotPlant2 before 2020-09-14. In class Pay2PayPayment in payment/Pay2PayPayment.php, there is an XXE vulnerability in the checkResult function. The user input ($_POST['xml']) is used for simplexml_load_string with…
- CVE-2020-25817MEDIUMCVSS 4.8EG 4.82021-06-08
SilverStripe through 4.6.0-rc1 has an XXE Vulnerability in CSSContentParser. A developer utility meant for parsing HTML within unit tests can be vulnerable to XML External Entity (XXE) attacks. When this developer utility is misused for pu…
- CVE-2020-25911CRITICALCVSS 9.1EG 9.12021-10-31
A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).
- CVE-2020-25912CRITICALCVSS 9.1EG 9.12021-10-31
A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).
- CVE-2020-26064HIGHCVSS 8.1EG 8.12023-08-04
A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper handling…
- CVE-2020-26066MEDIUMCVSS 6.5EG 6.52024-11-18
A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper hand…
- CVE-2020-26229LOWCVSS 3.7EG 3.72020-11-23
TYPO3 is an open source PHP based web content management system. In TYPO3 from version 10.4.0, and before version 10.4.10, RSS widgets are susceptible to XML external entity processing. This vulnerability is reasonable, but is theoretical …
- CVE-2020-26247LOWCVSS 2.6EG 2.62020-12-30
Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default…
- CVE-2020-26513MEDIUMCVSS 5.5EG 5.52020-12-07
An issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The ReqIF XML data, used by the codebeamer ALM application to import projects, is parsed by insecurely configured software components, which can be abused for XML Ext…
- CVE-2020-26564MEDIUMCVSS 6.5EG 6.52021-07-31
ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a generic survey template (containing a link to this .css file), and import this .xml file at the surve…
- CVE-2020-26705CRITICALCVSS 9.1EG 9.12021-10-31
The parseXML function in Easy-XML 0.5.0 was discovered to have a XML External Entity (XXE) vulnerability which allows for an attacker to expose sensitive data or perform a denial of service (DOS) via a crafted external entity entered into …
- CVE-2020-26708HIGHCVSS 7.5EG 7.52023-06-29
requests-xml v0.2.3 was discovered to contain an XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via a crafted XML file.
- CVE-2020-26709HIGHCVSS 7.5EG 7.52023-06-29
py-xml v1.0 was discovered to contain an XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via a crafted XML file.
- CVE-2020-26710HIGHCVSS 7.5EG 7.52023-06-29
easy-parse v0.1.1 was discovered to contain a XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via a crafted XML file.
- CVE-2020-26981MEDIUMCVSS 6.5EG 6.52021-01-12
A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). When opening a specially crafted xml file, the application could disclose arbitrary files to remote attackers. This i…
- CVE-2020-27017MEDIUMCVSS 4.9EG 4.92020-11-09
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an XML External Entity Processing (XXE) vulnerability which could allow an authenticated administrator to read arbitrary local files. An attacker must …
- CVE-2020-27148HIGHCVSS 7.1EG 7.12021-01-12
The TIBCO EBX Add-on for Oracle Hyperion EPM, TIBCO EBX Data Exchange Add-on, and TIBCO EBX Insight Add-on components of TIBCO Software Inc.'s TIBCO EBX Add-ons contain a vulnerability that theoretically allows a low privileged attacker wi…
- CVE-2020-27858HIGHCVSS 7.5EG 8.72021-01-20
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CA Arcserve D2D 16.5. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getNews metho…
- CVE-2020-28387MEDIUMCVSS 5.5EG 5.52021-03-15
A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP13), Solid Edge SE2021 (All Versions < SE2021MP3). When opening a specially crafted SEECTCXML file, the application could disclose arbitrary files to remote a…
- CVE-2020-28734HIGHCVSS 8.8EG 8.82020-12-30
Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.
- CVE-2020-28736HIGHCVSS 8.8EG 8.82020-12-30
Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (therefore, only available to the Manager role).
- CVE-2020-29436MEDIUMCVSS 6.5EG 6.52020-12-17
Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain access to content outside of NXRM via an XXE vulnerability. Fixed in version 3.29.0.
- CVE-2020-3256MEDIUMCVSS 4.9EG 4.92020-05-06
A vulnerability in the web-based management interface of Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) Software could allow an authenticated, remote attacker to gain read access to information that is stored on an affected syste…
- CVE-2020-3405HIGHCVSS 7.3EG 7.32020-07-16
A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper handling o…
- CVE-2020-35123MEDIUMCVSS 6.5EG 6.52020-12-17
In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in the saml consumer store extension, which is vulnerable to XXE attacks. This has been fixed in Zimbra Collaboration Suit…
- CVE-2020-35604CRITICALCVSS 9.8EG 9.82020-12-21
An XXE attack can occur in Kronos WebTA 5.0.4 when SAML is used.
- CVE-2020-36124MEDIUMCVSS 6.5EG 6.52021-05-07
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by XML External Entity (XXE) injection. An authenticated attacker can compromise the private keys of a JWT token and reuse them to manipulate the access tokens to access t…
- CVE-2020-36640MEDIUMCVSS 5.5EG 5.52023-01-05
A vulnerability, which was classified as problematic, was found in bonitasoft bonita-connector-webservice up to 1.3.0. This affects the function TransformerConfigurationException of the file src/main/java/org/bonitasoft/connectors/ws/Secur…
- CVE-2020-36641MEDIUMCVSS 5.5EG 5.52023-01-05
A vulnerability classified as problematic was found in gturri aXMLRPC up to 1.12.0. This vulnerability affects the function ResponseParser of the file src/main/java/de/timroes/axmlrpc/ResponseParser.java. The manipulation leads to xml exte…
- CVE-2020-37192MEDIUMCVSS 6.2EG 6.22026-02-11
MSN Password Recovery 1.30 contains an XML external entity injection vulnerability that allows attackers to read local system files through crafted XML input. Attackers can exploit the 'Favorites' tab by injecting a malicious XML file that…
- CVE-2020-4246HIGHCVSS 7.1EG 7.12020-05-28
IBM Security Identity Governance and Intelligence 5.2.6 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume …
- CVE-2020-4300HIGHCVSS 8.2EG 8.22021-06-01
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM…
- CVE-2020-4377CRITICALCVSS 9.1EG 9.12020-08-03
IBM Cognos Anaytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM …
- CVE-2020-4462HIGHCVSS 8.2EG 8.22020-07-16
IBM Sterling External Authentication Server 6.0.1, 6.0.0, 2.4.3.2, and 2.4.2 and IBM Sterling Secure Proxy 6.0.1, 6.0.0, 3.4.3, and 3.4.2 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at…
- CVE-2020-4463HIGHCVSS 8.2EG 8.22020-07-29
IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory r…
- CVE-2020-4481HIGHCVSS 8.2EG 8.22020-08-05
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information o…
- CVE-2020-4509HIGHCVSS 7.6EG 7.62020-06-04
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Forc…
- CVE-2020-4510MEDIUMCVSS 5.5EG 5.52020-07-14
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Forc…
- CVE-2020-4606MEDIUMCVSS 4.4EG 4.42021-01-08
IBM Security Verify Privilege Manager 10.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A local attacker could exploit this vulnerability to expose sensitive information or consume memory resourc…
- CVE-2020-4643HIGHCVSS 7.5EG 7.52020-09-21
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information. IBM X-Forc…
Map vulnerabilities like CWE-611 to your infrastructure
EchelonGraph correlates every CVE — across CWE-611 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →