CWE-611— Improper Restriction of XML External Entity Reference (XXE)
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.— MITRE CWE catalog
1,275 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-611page 14 of 26
- CVE-2021-22501MEDIUMCVSS 5.3EG 5.32024-12-19
Improper Restriction of XML External Entity Reference vulnerability in OpenText™ Operations Bridge Manager allows Input Data Manipulation. The vulnerability could be exploited to confidential information This issue affects Operations…
- CVE-2021-22523HIGHCVSS 7.6EG 7.62021-07-22
XML External Entity vulnerability in Micro Focus Verastream Host Integrator, affecting version 7.8 Update 1 and earlier versions. The vulnerability could allow the control of web browser and hijacking user sessions.
- CVE-2021-23418MEDIUMCVSS 6.3EG 6.32021-07-29
The package glances before 3.2.1 are vulnerable to XML External Entity (XXE) Injection via the use of Fault to parse untrusted XML data, which is known to be vulnerable to XML attacks.
- CVE-2021-23463HIGHCVSS 8.1EG 8.12021-12-10
The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML class object, when it receives parsed string data from org.h2.jdbc.JdbcResultSet.getSQLXML()…
- CVE-2021-23792HIGHCVSS 7.3EG 7.32022-05-06
The package com.twelvemonkeys.imageio:imageio-metadata before 3.7.1 are vulnerable to XML External Entity (XXE) Injection due to an insecurely initialized XML parser for reading XMP Metadata. An attacker can exploit this vulnerability if t…
- CVE-2021-23899CRITICALCVSS 9.8EG 9.82021-01-13
OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input. This allows an attacker to inject arbitrary HTML or XML into embedding documents.
- CVE-2021-23901CRITICALCVSS 9.1EG 9.12021-01-25
An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML external entity injection (also known as XXE) is a web security vulnerability that allows an atta…
- CVE-2021-2401CRITICALCVSS 5.3EG 9.02021-07-21
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability a…
- CVE-2021-25163HIGHCVSS 8.1EG 8.12021-04-29
A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.
- CVE-2021-25164MEDIUMCVSS 6.5EG 6.52021-04-28
A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.
- CVE-2021-25165HIGHCVSS 8.1EG 8.12021-04-28
A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.
- CVE-2021-25951HIGHCVSS 7.5EG 7.52021-06-30
XXE vulnerability in 'XML2Dict' version 0.2.2 allows an attacker to cause a denial of service.
- CVE-2021-26703CRITICALCVSS 9.8EG 9.82021-03-01
EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted JSON/XML input to a cgi/ajax/phrase URI.
- CVE-2021-26969MEDIUMCVSS 6.5EG 6.52021-03-05
A remote authenticated authenticated xml external entity (xxe) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Due to improper restrictions on XML entities a vulnerability exists in the web-…
- CVE-2021-27184HIGHCVSS 7.5EG 7.52021-02-11
Pelco Digital Sentry Server 7.18.72.11464 has an XML External Entity vulnerability (exploitable via the DTD parameter entities technique), resulting in disclosure and retrieval of arbitrary data on the affected node via an out-of-band (OOB…
- CVE-2021-27492MEDIUMCVSS 5.5EG 5.52021-05-27
When opening a specially crafted 3DXML file, the application containing Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior could disclose arbitrary fi…
- CVE-2021-27604MEDIUMCVSS 6.5EG 6.52021-04-14
In order to prevent XML External Entity vulnerability in SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - Enterprise Service Repository JAVA Mappings), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50, SAP recommends to refe…
- CVE-2021-27635MEDIUMCVSS 6.5EG 6.52021-06-09
SAP NetWeaver AS for JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker authenticated as an administrator to connect over a network and submit a specially crafted XML file in the application because of missing XML Validation…
- CVE-2021-27736MEDIUMCVSS 6.5EG 6.52021-04-22
FusionAuth fusionauth-samlv2 before 0.5.4 allows XXE attacks via a forged AuthnRequest or LogoutRequest because parseFromBytes uses javax.xml.parsers.DocumentBuilderFactory unsafely.
- CVE-2021-27741CRITICALCVSS 9.1EG 9.12021-08-13
" Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection"
- CVE-2021-27777HIGHCVSS 7.5EG 7.52022-05-12
XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validation. Attackers can exploit this vulnerability to manipulate XML content and inject malicious…
- CVE-2021-27931CRITICALCVSS 9.1EG 9.12021-03-03
LumisXP (aka Lumis Experience Platform) before 10.0.0 allows unauthenticated blind XXE via an API request to PageControllerXml.jsp. One can send a request crafted with an XXE payload and achieve outcomes such as reading local server files …
- CVE-2021-28110HIGHCVSS 7.5EG 7.52021-03-19
/exec in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a vulnerability in its XML parser.
- CVE-2021-28684MEDIUMCVSS 4.3EG 4.32021-06-21
The XML parser used in ConeXware PowerArchiver before 20.10.02 allows processing of external entities, which might lead to exfiltration of local files over the network (via an XXE attack).
- CVE-2021-28973MEDIUMCVSS 4.9EG 4.92021-04-13
The XML Import functionality of the Administration console in Perforce Helix ALM 2020.3.1 Build 22 accepts XML input data that is parsed by insecurely configured software components, leading to XXE attacks.
- CVE-2021-29140HIGHCVSS 8.2EG 8.22021-04-29
A remote XML external entity (XXE) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.9, 6.7.14-HF1. Aruba has released patches for Aruba ClearPass Policy Manager that address this security vulne…
- CVE-2021-29421HIGHCVSS 7.5EG 7.52021-04-01
models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries.
- CVE-2021-29447CRITICALCVSS 7.1EG 9.02021-04-15
Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to inter…
- CVE-2021-29620HIGHCVSS 7.5EG 7.52021-06-23
Report portal is an open source reporting and analysis framework. Starting from version 3.1.0 of the service-api XML parsing was introduced. Unfortunately the XML parser was not configured properly to prevent XML external entity (XXE) atta…
- CVE-2021-29831HIGHCVSS 8.1EG 8.12021-09-21
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive inf…
- CVE-2021-29997MEDIUMCVSS 5.3EG 5.32021-04-13
An issue was discovered in Wind River VxWorks 7 before 21.03. A specially crafted packet may lead to buffer over-read on IKE.
- CVE-2021-30006HIGHCVSS 7.5EG 7.52021-05-11
In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure.
- CVE-2021-30137HIGHCVSS 7.7EG 7.72021-09-15
Assyst 10 SP7.5 has authenticated XXE leading to SSRF via XML unmarshalling. The application allows users to send JSON or XML data to the server. It was possible to inject malicious XML data through several access points.
- CVE-2021-30201HIGHCVSS 7.5EG 7.52021-07-09
The API /vsaWS/KaseyaWS.asmx can be used to submit XML to the system. When this XML is processed (external) entities are insecurely processed and fetched by the system and returned to the attacker. Detailed description Given the following …
- CVE-2021-3055MEDIUMCVSS 6.5EG 6.52021-09-08
An improper restriction of XML external entity (XXE) reference vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to read any arbitrary file from the file system and send a specifically craf…
- CVE-2021-31842MEDIUMCVSS 5.0EG 5.52021-09-17
XML Entity Expansion injection vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2021 Update allows a local user to initiate high CPU and memory consumption resulting in a Denial of Service attack throug…
- CVE-2021-32754MEDIUMCVSS 5.3EG 5.32021-07-12
FlowDroid is a data flow analysis tool. FlowDroid versions prior to 2.9.0 contained an XML external entity (XXE) vulnerability that allowed an attacker who had control over the source/sink definition file in XML format to read files from e…
- CVE-2021-32925MEDIUMCVSS 6.5EG 6.52021-05-13
admin/user_import.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities.
- CVE-2021-32972MEDIUMCVSS 5.5EG 5.52021-07-09
Panasonic FPWIN Pro, all Versions 7.5.1.1 and prior, allows an attacker to craft a project file specifying a URI that causes the XML parser to access the URI and embed the contents, which may allow the attacker to disclose information that…
- CVE-2021-3312MEDIUMCVSS 6.5EG 6.52021-10-08
An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfiltrate files from the server's file system by uploading a crafted SVG document.
- CVE-2021-33208HIGHCVSS 7.2EG 7.22022-03-30
The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA allows XXE attacks via a malicious XML configuration file.
- CVE-2021-33813HIGHCVSS 7.5EG 7.52021-06-16
An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.
- CVE-2021-33950HIGHCVSS 7.5EG 7.52023-02-17
An issue discovered in OpenKM v6.3.10 allows attackers to obtain sensitive information via the XMLTextExtractor function.
- CVE-2021-34436CRITICALCVSS 9.8EG 9.82021-09-02
In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension. This extension uses lsp4xml (recently renamed to LemMinX) in order to provide language supp…
- CVE-2021-34706MEDIUMCVSS 6.4EG 6.42021-10-06
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information or conduct a server-side request forgery (SSRF) attack through an a…
- CVE-2021-34823CRITICALCVSS 9.1EG 9.12021-08-13
The ON24 ScreenShare (aka DesktopScreenShare.app) plugin before 2.0 for macOS allows remote file access via its built-in HTTP server. This allows unauthenticated remote users to retrieve files accessible to the logged-on macOS user. When a…
- CVE-2021-35066CRITICALCVSS 9.8EG 9.82021-06-21
An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.
- CVE-2021-35201MEDIUMCVSS 6.5EG 6.52021-09-30
NEI in NETSCOUT nGeniusONE 6.3.0 build 1196 allows XML External Entity (XXE) attacks.
- CVE-2021-35496HIGHCVSS 7.5EG 7.52021-10-12
The XMLA Connections component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Ser…
- CVE-2021-36172MEDIUMCVSS 4.3EG 4.32021-11-02
An improper restriction of XML external entity reference vulnerability in the parser of XML responses of FortiPortal before 6.0.6 may allow an attacker who controls the producer of XML reports consumed by FortiPortal to trigger a denial of…
Map vulnerabilities like CWE-611 to your infrastructure
EchelonGraph correlates every CVE — across CWE-611 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →