CWE-611— Improper Restriction of XML External Entity Reference (XXE)
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.— MITRE CWE catalog
1,275 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-611page 15 of 26
- CVE-2021-37178MEDIUMCVSS 5.5EG 5.52021-08-10
A vulnerability has been identified in Solid Edge SE2021 (All Versions < SE2021MP7). An XML external entity injection vulnerability in the underlying XML parser could cause the affected application to disclose arbitrary files to remote att…
- CVE-2021-37425CRITICALCVSS 9.1EG 9.12021-08-10
Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobiletogetherserver.cfg and then reading the certificate and private key.
- CVE-2021-38298CRITICALCVSS 9.8EG 9.82021-10-07
Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE.
- CVE-2021-3836MEDIUMCVSS 5.5EG 5.52021-12-14
dbeaver is vulnerable to Improper Restriction of XML External Entity Reference
- CVE-2021-38555CRITICALCVSS 9.1EG 9.12021-09-11
An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to affect Any23 versions < 2.5. XML external entity injection (also known as XXE) is a web security vulnerability that allo…
- CVE-2021-38584HIGHCVSS 7.2EG 7.22021-08-11
The WHM Locale Upload feature in cPanel before 98.0.1 allows XXE attacks (SEC-585).
- CVE-2021-3869HIGHCVSS 7.5EG 7.52021-10-19
corenlp is vulnerable to Improper Restriction of XML External Entity Reference
- CVE-2021-3878CRITICALCVSS 9.8EG 9.82021-10-15
corenlp is vulnerable to Improper Restriction of XML External Entity Reference
- CVE-2021-3902CRITICALCVSS 9.8EG 9.82024-11-15
An improper restriction of external entities (XXE) vulnerability in dompdf/dompdf's SVG parser allows for Server-Side Request Forgery (SSRF) and deserialization attacks. This issue affects all versions prior to 2.0.0. The vulnerability can…
- CVE-2021-39239HIGHCVSS 7.5EG 7.52021-09-16
A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including exposing the contents of local files to a remote server.
- CVE-2021-39371HIGHCVSS 7.5EG 7.52021-08-23
An XML external entity (XXE) injection in PyWPS before 4.4.5 allows an attacker to view files on the application server filesystem by assigning a path to the entity. OWSLib 0.24.1 may also be affected.
- CVE-2021-40356HIGHCVSS 7.5EG 7.52021-09-14
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (All versions < V13.1.0.5), Teamcenter V13.2 (All versions < 13.2.0.2). The application conta…
- CVE-2021-40439MEDIUMCVSS 6.5EG 6.52021-10-07
Apache OpenOffice has a dependency on expat software. Versions prior to 2.1.0 were subject to CVE-2013-0340 a "Billion Laughs" entity expansion denial of service attack and exploit via crafted XML files. ODF files consist of a set of XML f…
- CVE-2021-40500HIGHCVSS 7.5EG 7.52021-10-12
SAP BusinessObjects Business Intelligence Platform (Crystal Reports) - versions 420, 430, allows an unauthenticated attacker to exploit missing XML validations at endpoints to read sensitive data. These endpoints are normally exposed over …
- CVE-2021-40510HIGHCVSS 7.5EG 7.52022-06-21
XML eXternal Entity (XXE) in OBDA systems’ Mastro 1.0 allows remote attackers to read system files via custom DTDs.
- CVE-2021-40722CRITICALCVSS 9.8EG 9.82022-01-13
AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) injection vulnerability that could be abused by an attacker to achieve RCE.
- CVE-2021-41042MEDIUMCVSS 5.3EG 5.32022-07-07
In Eclipse Lyo versions 1.0.0 to 4.1.0, a TransformerFactory is initialized with the defaults that do not restrict DTD loading when working with RDF/XML. This allows an attacker to cause an external DTD to be retrieved.
- CVE-2021-41098HIGHCVSS 7.5EG 7.52021-09-27
Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri v1.12.4 and earlier, on JRuby only, the SAX parser resolves external entities by default. Users of Nokogiri on JRuby who pa…
- CVE-2021-41411CRITICALCVSS 9.8EG 9.82022-06-16
drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.
- CVE-2021-41770HIGHCVSS 7.5EG 7.52021-10-07
Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure.
- CVE-2021-42194HIGHCVSS 7.2EG 7.22022-03-20
The wechat_return function in /controller/Index.php of EyouCms V1.5.4-UTF8-SP3 passes the user's input directly into the simplexml_ load_ String function, which itself does not prohibit external entities, triggering a XML external entity (…
- CVE-2021-42537HIGHCVSS 5.9EG 7.52022-07-27
VISAM VBASE version 11.6.0.6 processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
- CVE-2021-42560HIGHCVSS 8.8EG 8.82022-01-12
An issue was discovered in CALDERA 2.9.0. The Debrief plugin receives base64 encoded "SVG" parameters when generating a PDF document. These SVG documents are parsed in an unsafe manner and can be leveraged for XXE attacks (e.g., File Exfil…
- CVE-2021-42646CRITICALCVSS 9.1EG 9.12022-05-11
XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; and WSO2 IS as Key Manager 5.7.0, 5.9.0, and 5.10.0; and WSO2 …
- CVE-2021-42776HIGHCVSS 7.7EG 7.72021-12-01
CloverDX Server before 5.11.2 and and 5.12.x before 5.12.1 allows XXE during configuration import.
- CVE-2021-4295CRITICALCVSS 5.5EG 9.82022-12-29
A vulnerability classified as problematic was found in ONC code-validator-api up to 1.0.30. This vulnerability affects the function vocabularyValidationConfigurations of the file src/main/java/org/sitenv/vocabularies/configuration/CodeVali…
- CVE-2021-43090CRITICALCVSS 9.8EG 9.82022-03-25
An XML External Entity (XXE) vulnerability exists in soa-model before 1.6.4 in the WSDLParser function.
- CVE-2021-4311CRITICALCVSS 5.5EG 9.82023-01-09
A vulnerability classified as problematic was found in Talend Open Studio for MDM. This vulnerability affects unknown code of the component XML Handler. The manipulation leads to xml external entity reference. The patch is identified as 31…
- CVE-2021-43142CRITICALCVSS 9.8EG 9.82022-03-30
An XML External Entity (XXE) vulnerability exists in wuta jox 1.16 in the readObject method in JOXSAXBeanInput.
- CVE-2021-43576MEDIUMCVSS 6.5EG 6.52021-11-12
Jenkins pom2config Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers with Overall/Read and Item/Read permissions to have Jenkins parse a crafted XML file that uses ext…
- CVE-2021-43577HIGHCVSS 7.1EG 7.12021-11-12
Jenkins OWASP Dependency-Check Plugin 5.1.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2021-43990MEDIUMCVSS 6.1EG 6.52022-04-20
The affected product is vulnerable to a network-based attack by threat actors supplying a crafted, malicious XML payload designed to trigger an external entity reference call.
- CVE-2021-44028MEDIUMCVSS 5.5EG 5.52021-12-22
XXE can occur in Quest KACE Desktop Authority before 11.2 because the log4net configuration file might be controlled by an attacker, a related issue to CVE-2018-1285.
- CVE-2021-44147MEDIUMCVSS 5.5EG 5.52021-11-22
An XML External Entity issue in Claris FileMaker Pro and Server (including WebDirect) before 19.4.1 allows a remote attacker to disclose local files via a crafted XML/Excel document and perform server-side request forgery attacks.
- CVE-2021-44477HIGHCVSS 7.5EG 7.52022-03-25
GE Gas Power ToolBoxST Version v04.07.05C suffers from an XML external entity (XXE) vulnerability using the DTD parameter entities technique that could result in disclosure and retrieval of arbitrary data on the affected node via an out-of…
- CVE-2021-44556CRITICALCVSS 9.1EG 9.12021-12-08
National Library of the Netherlands digger < 6697d1269d981e35e11f240725b16401b5ce3db5 is affected by a XML External Entity (XXE) vulnerability. Since XML parsing resolves external entities, a malicious XML stream could leak internal files …
- CVE-2021-44557CRITICALCVSS 9.1EG 9.12021-12-08
National Library of the Netherlands multiNER <= c0440948057afc6e3d6b4903a7c05e666b94a3bc is affected by an XML External Entity (XXE) vulnerability in multiNER/ner.py. Since XML parsing resolves external entities, a malicious XML stream cou…
- CVE-2021-45024CRITICALCVSS 9.8EG 9.82022-06-17
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE).
- CVE-2021-45096MEDIUMCVSS 4.7EG 4.72021-12-16
KNIME Analytics Platform before 4.5.0 is vulnerable to XXE (external XML entity injection) via a crafted workflow file (.knwf), aka AP-17730.
- CVE-2021-45981CRITICALCVSS 9.8EG 9.82022-06-02
NetScout nGeniusONE 6.3.2 allows an XML External Entity (XXE) attack.
- CVE-2021-46365HIGHCVSS 7.8EG 7.82022-02-11
An issue in the Export function of Magnolia v6.2.3 and below allows attackers to execute XML External Entity attacks via a crafted XLF file.
- CVE-2021-46660CRITICALCVSS 9.8EG 9.82022-01-30
Signiant Manager+Agents before 15.1 allows XML External Entity (XXE) attacks.
- CVE-2021-47621HIGHCVSS 7.5EG 7.52024-06-21
ClassGraph before 4.8.112 was not resistant to XML eXternal Entity (XXE) attacks.
- CVE-2022-0198HIGHCVSS 7.1EG 7.12022-01-13
corenlp is vulnerable to Improper Restriction of XML External Entity Reference
- CVE-2022-0217HIGHCVSS 7.5EG 7.52022-08-26
It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in parsed XML data. Given suitable attacker input, this results in expansion of recursive entity reference…
- CVE-2022-0219MEDIUMCVSS 5.5EG 5.52022-01-20
Improper Restriction of XML External Entity Reference in GitHub repository skylot/jadx prior to 1.3.2.
- CVE-2022-0221MEDIUMCVSS 5.5EG 5.52022-04-13
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could result in information disclosure when opening a malicious solution file provided by an attacker with SCADAPack Workbench. This could be exploi…
- CVE-2022-0239CRITICALCVSS 9.8EG 9.82022-01-17
corenlp is vulnerable to Improper Restriction of XML External Entity Reference
- CVE-2022-0265CRITICALCVSS 9.8EG 9.82022-03-03
Improper Restriction of XML External Entity Reference in GitHub repository hazelcast/hazelcast in 5.1-BETA-1.
- CVE-2022-0272CRITICALCVSS 9.8EG 9.82022-04-21
Improper Restriction of XML External Entity Reference in GitHub repository detekt/detekt prior to 1.20.0.
Map vulnerabilities like CWE-611 to your infrastructure
EchelonGraph correlates every CVE — across CWE-611 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →