CWE-611— Improper Restriction of XML External Entity Reference (XXE)
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.— MITRE CWE catalog
1,275 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-611page 16 of 26
- CVE-2022-0839CRITICALCVSS 9.8EG 9.82022-03-04
Improper Restriction of XML External Entity Reference in GitHub repository liquibase/liquibase prior to 4.8.0.
- CVE-2022-0861LOWCVSS 3.5EG 3.82022-03-23
A XML Extended entity vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote administrator attacker to upload a malicious XML file through the extension import functionality. The impact is lim…
- CVE-2022-1018MEDIUMCVSS 5.5EG 5.52022-04-01
When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe call within a dynamic link library file. An attacker could exploit this to pass data from lo…
- CVE-2022-1331MEDIUMCVSS 5.5EG 5.52022-05-03
In four instances DMARS (All versions prior to v2.1.10.24) does not properly restrict references of XML external entities while processing specific project files, which may allow unauthorized information disclosure.
- CVE-2022-1700CRITICALCVSS 7.5EG 9.82022-09-12
Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine of Forcepoint Data Loss Prevention (DLP), which is also leveraged by Forcepoint One Endpoint (F1E), Web Security Content Gateway, Email Securi…
- CVE-2022-1704CRITICALCVSS 7.6EG 9.82022-08-05
Due to an XML external entity reference, the software parses XML in the backup/restore functionality without XML security flags, which may lead to a XXE attack while restoring the backup.
- CVE-2022-20780CRITICALCVSS 9.9EG 9.92022-05-04
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data…
- CVE-2022-20938MEDIUMCVSS 4.3EG 4.32022-11-15
A vulnerability in the module import function of the administrative interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to view sensitive information. This vulnerability is due to …
- CVE-2022-21205HIGHCVSS 7.5EG 7.52022-02-09
Improper restriction of XML external entity reference in DSP Builder Pro for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an unauthenticated user to potentially enable information disclosure via network access.
- CVE-2022-21220HIGHCVSS 7.8EG 7.82022-02-09
Improper restriction of XML external entity for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-21282MEDIUMCVSS 5.3EG 5.32022-01-19
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: …
- CVE-2022-2131CRITICALCVSS 8.5EG 9.82022-07-25
OpenKM Community Edition in its 6.3.10 version and before was using XMLReader parser in XMLTextExtractor.java file without the required security flags, allowing an attacker to perform a XML external entity injection attack.
- CVE-2022-21949HIGHCVSS 8.8EG 8.82022-05-03
A Improper Restriction of XML External Entity Reference vulnerability in SUSE Open Build Service allows remote attackers to reference external entities in certain operations. This can be used to gain information from the server that can be…
- CVE-2022-22358HIGHCVSS 7.1EG 7.12022-07-19
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive informa…
- CVE-2022-22486CRITICALCVSS 10.0EG 10.02023-02-03
IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory …
- CVE-2022-22489CRITICALCVSS 9.1EG 9.12022-08-19
IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume m…
- CVE-2022-22774CRITICALCVSS 8.6EG 9.12022-05-10
The DOM XML parser and SAX XML parser components of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center, TIBCO Managed File Transfer Command Center, TIBCO Managed File Transfer Internet Server, and TIBCO Managed File Transfer …
- CVE-2022-22795CRITICALCVSS 6.8EG 9.12022-03-10
Signiant - Manager+Agents XML External Entity (XXE) - Extract internal files of the affected machine An attacker can read all the system files, the product is running with root on Linux systems and nt/authority on windows systems, which al…
- CVE-2022-22835MEDIUMCVSS 6.5EG 6.52022-03-10
An issue was discovered in OverIT Geocall before version 8.0. An authenticated user who has the Test Trasformazione XSL functionality enabled can exploit a XXE vulnerability to read arbitrary files from the filesystem.
- CVE-2022-22977HIGHCVSS 7.1EG 7.12022-05-24
VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE) vulnerability. A malicious actor with non-administrative local user privileges in the Windows guest OS, where VMware Tools is installed, may exploit …
- CVE-2022-23031MEDIUMCVSS 4.9EG 4.92022-01-25
On BIG-IP FPS, ASM, and Advanced WAF versions 16.1.x before 16.1.1, 15.1.x before 15.1.4, and 14.1.x before 14.1.4.4, an XML External Entity (XXE) vulnerability exists in an undisclosed page of the F5 Advanced Web Application Firewall (Adv…
- CVE-2022-23170CRITICALCVSS 5.9EG 9.82022-06-24
SysAid - Okta SSO integration - was found vulnerable to XML External Entity Injection vulnerability. Any SysAid environment that uses the Okta SSO integration might be vulnerable. An unauthenticated attacker could exploit the XXE vulnerabi…
- CVE-2022-2330MEDIUMCVSS 6.5EG 6.52022-08-30
Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 allows a remote attacker to cause the DLP Agent to access a local service that the attacker wouldn't usually have access to v…
- CVE-2022-23640CRITICALCVSS 9.8EG 9.82022-03-02
Excel-Streaming-Reader is an easy-to-use implementation of a streaming Excel reader using Apache POI. Prior to xlsx-streamer 2.1.0, the XML parser that was used did apply all the necessary settings to prevent XML Entity Expansion issues. U…
- CVE-2022-2414CRITICALCVSS 7.5EG 9.02022-07-29
Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.
- CVE-2022-24340CRITICALCVSS 9.8EG 9.82022-02-25
In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible.
- CVE-2022-24449CRITICALCVSS 9.8EG 9.82022-04-28
Solar appScreener through 3.10.4, when a valid license is not present, allows XXE and SSRF attacks via a crafted XML document.
- CVE-2022-2458HIGHCVSS 8.2EG 8.22022-08-10
XML external entity injection(XXE) is a vulnerability that allows an attacker to interfere with an application's processing of XML data. This attack occurs when XML input containing a reference to an external entity is processed by a weakl…
- CVE-2022-24898MEDIUMCVSS 4.9EG 4.92022-04-28
org.xwiki.commons:xwiki-commons-xml is a common module used by other XWiki top level projects. Starting in version 2.7 and prior to versions 12.10.10, 13.4.4, and 13.8-rc-1, it is possible for a script to access any file accessing to the u…
- CVE-2022-25209HIGHCVSS 8.8EG 8.82022-02-15
Jenkins Chef Sinatra Plugin 1.20 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2022-25312CRITICALCVSS 9.1EG 9.12022-03-05
An XML external entity (XXE) injection vulnerability was discovered in the Any23 RDFa XSLTStylesheet extractor and is known to affect Any23 versions < 2.7. XML external entity injection (also known as XXE) is a web security vulnerability t…
- CVE-2022-25628HIGHCVSS 8.8EG 8.82022-12-16
An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Identity Manager 14.4
- CVE-2022-26661MEDIUMCVSS 6.5EG 6.52022-03-10
An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through …
- CVE-2022-27193MEDIUMCVSS 6.1EG 6.12022-03-15
CVRF-CSAF-Converter before 1.0.0-rc2 resolves XML External Entities (XXE). This leads to the inclusion of arbitrary (local) file content into the generated output document. An attacker can exploit this to disclose information from the syst…
- CVE-2022-2759HIGHCVSS 5.5EG 8.62022-08-31
Delta Electronics Delta Robot Automation Studio (DRAS) versions prior to 1.13.20 are affected by improper restrictions where the software processes an XML document that can contain XML entities with URIs that resolve to documents outside o…
- CVE-2022-27873HIGHCVSS 7.8EG 7.82022-07-29
An attacker can force the victim’s device to perform arbitrary HTTP requests in WAN through a malicious SVG file being parsed by Autodesk Fusion 360’s document parser. The vulnerability exists in the application’s ‘Insert SVG’ pr…
- CVE-2022-28140HIGHCVSS 8.1EG 8.12022-03-29
Jenkins Flaky Test Handler Plugin 1.2.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2022-28154HIGHCVSS 8.1EG 8.12022-03-29
Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2022-28155HIGHCVSS 8.1EG 8.12022-03-29
Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2022-28219CRITICALCVSS 9.8EG 9.82022-04-05
Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.
- CVE-2022-2838MEDIUMCVSS 5.3EG 5.32022-08-16
In Eclipse Sphinx™ before version 0.13.1, Apache Xerces XML Parser was used without disabling processing of referenced external entities allowing the injection of arbitrary definitions which is able to access local files and expose their…
- CVE-2022-28890CRITICALCVSS 9.8EG 9.82022-05-05
A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow external entities.
- CVE-2022-29265HIGHCVSS 7.5EG 7.52022-04-30
Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration. The Standard Content Viewer service attempts to resolve XML External Entity references when viewing formatted X…
- CVE-2022-29801HIGHCVSS 7.5EG 7.52022-05-20
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.13), Teamcenter V13.0 (All versions < V13.0.0.9). The application contains a XML External Entity Injection (XXE) vulnerability. This could allow an attacker to…
- CVE-2022-29943MEDIUMCVSS 6.5EG 6.52022-05-04
Talend Administration Center has a vulnerability that allows an authenticated user to use XML External Entity (XXE) processing to achieve read access as root on the remote filesystem. The issue is fixed for versions 8.0.x in TPS-5189, vers…
- CVE-2022-30971HIGHCVSS 8.8EG 8.82022-05-17
Jenkins Storable Configs Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2022-31261HIGHCVSS 7.5EG 7.52022-05-24
An XXE issue was discovered in Morpheus through 5.2.16 and 5.4.x through 5.4.4. A successful attack requires a SAML identity provider to be configured. In order to exploit the vulnerability, the attacker must know the unique SAML callback …
- CVE-2022-31447HIGHCVSS 7.5EG 7.52022-06-14
An XML external entity (XXE) injection vulnerability in Magicpin v3.4 allows attackers to access sensitive database information via a crafted SVG file.
- CVE-2022-31471HIGHCVSS 7.5EG 7.52022-07-26
untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts XML external entity references. By exploiting this vulnerability, a remote unauthenticated attacker may read the c…
- CVE-2022-31678CRITICALCVSS 9.1EG 9.12022-10-28
VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit this issue leading to a denial-of-service condition or unintended information d…
Map vulnerabilities like CWE-611 to your infrastructure
EchelonGraph correlates every CVE — across CWE-611 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →