CWE-611— Improper Restriction of XML External Entity Reference (XXE)
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.— MITRE CWE catalog
1,275 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-611page 18 of 26
- CVE-2022-45396CRITICALCVSS 9.8EG 9.82022-11-15
Jenkins SourceMonitor Plugin 0.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2022-45397CRITICALCVSS 9.8EG 9.82022-11-15
Jenkins OSF Builder Suite : : XML Linter Plugin 1.0.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2022-45400CRITICALCVSS 9.8EG 9.82022-11-15
Jenkins JAPEX Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2022-45468MEDIUMCVSS 5.5EG 5.52023-03-21
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
- CVE-2022-45588CRITICALCVSS 7.8EG 9.82023-02-03
All versions before R2022-09 of Talend's Remote Engine Gen 2 are potentially vulnerable to XML External Entity (XXE) type of attacks. Users should download the R2022-09 release or later and use it in place of the previous version. Talend R…
- CVE-2022-45876MEDIUMCVSS 5.5EG 5.52023-04-26
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
- CVE-2022-4607CRITICALCVSS 5.5EG 9.82022-12-18
A vulnerability was found in 3D City Database OGC Web Feature Service up to 5.2.0. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to xml external entity reference. Upgrading to version …
- CVE-2022-46286MEDIUMCVSS 5.5EG 5.52023-03-21
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
- CVE-2022-46300MEDIUMCVSS 5.5EG 5.52023-03-21
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
- CVE-2022-46682CRITICALCVSS 9.8EG 9.82022-12-12
Jenkins Plot Plugin 2.1.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2022-46751HIGHCVSS 8.2EG 8.22023-08-21
Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache Ivy.This issue affects any version of Apache Ivy prior to 2.5.2. When Apache Ivy prior to …
- CVE-2022-46827MEDIUMCVSS 3.9EG 5.52022-12-08
In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was possible.
- CVE-2022-47514HIGHCVSS 8.8EG 8.82022-12-18
An XML external entity (XXE) injection vulnerability in XML-RPC.NET before 2.5.0 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, as demonstrated by a pingback.aspx POST request.
- CVE-2022-47873CRITICALCVSS 9.8EG 9.82023-01-31
Netcad KEOS 1.0 is vulnerable to XML External Entity (XXE) resulting in SSRF with XXE (remote).
- CVE-2022-4818MEDIUMCVSS 5.5EG 5.52022-12-28
A vulnerability was found in Talend Open Studio for MDM. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file org.talend.mdm.core/src/com/amalto/core/storage/SystemStorageWrapper.java.…
- CVE-2022-48565CRITICALCVSS 9.8EG 9.82023-08-22
An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.
- CVE-2022-50899MEDIUMCVSS 6.5EG 6.52026-01-13
Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in PDF rendering that allows attackers to retrieve arbitrary files from the server. Attackers can exploit the insecure XML parser by crafting a malicious XML docum…
- CVE-2023-0871MEDIUMCVSS 5.4EG 5.42023-08-11
XXE injection in /rtc/post/ endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to XML external entity (XXE) injection, which can be used for instance to force Horizon to make arbitrary …
- CVE-2023-1288CRITICALCVSS 6.8EG 9.82023-03-09
An XML External Entity injection (XXE) vulnerability in ENOVIA Live Collaboration V6R2013xE allows an attacker to read local files on the server.
- CVE-2023-20030MEDIUMCVSS 6.0EG 6.02023-04-05
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information, conduct a server-side request forgery (SSRF) attack through an aff…
- CVE-2023-20052MEDIUMCVSS 5.3EG 5.32023-03-01
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauth…
- CVE-2023-20173MEDIUMCVSS 4.9EG 4.92023-05-18
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read arbitrary files or conduct a server-side request forgery (SSRF) attack through an …
- CVE-2023-20174MEDIUMCVSS 4.9EG 4.92023-05-18
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read arbitrary files or conduct a server-side request forgery (SSRF) attack through an …
- CVE-2023-20855HIGHCVSS 8.8EG 8.82023-02-22
VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orchestrator, may be able to use specially crafted input to bypass XML parsing restrictions lea…
- CVE-2023-20918CRITICALCVSS 9.8EG 9.82023-07-13
In getPendingIntentLaunchFlags of ActivityOptions.java, there is a possible elevation of privilege due to a confused deputy with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2023-2161MEDIUMCVSS 5.0EG 5.02023-05-16
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized read access to the file system when a malicious configuration file is loaded on to the software by a local user.
- CVE-2023-21862HIGHCVSS 8.1EG 8.12023-01-18
Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: XML Security component). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attac…
- CVE-2023-22274HIGHCVSS 7.5EG 7.52023-11-17
Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to information disclosure by an unauthenticated attacker. Exploitation of this i…
- CVE-2023-22322MEDIUMCVSS 5.5EG 5.52023-01-30
Improper restriction of XML external entity reference (XXE) vulnerability exists in OMRON CX-Motion Pro 1.4.6.013 and earlier. If a user opens a specially crafted project file created by an attacker, sensitive information in the file syste…
- CVE-2023-22377HIGHCVSS 7.4EG 7.42023-02-15
Improper restriction of XML external entity reference (XXE) vulnerability exists in tsClinical Define.xml Generator all versions (v1.0.0 to v1.4.0) and tsClinical Metadata Desktop Tools Version 1.0.3 to Version 1.1.0. If this vulnerability…
- CVE-2023-22624HIGHCVSS 7.5EG 7.52023-01-17
Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks.
- CVE-2023-22832HIGHCVSS 7.5EG 7.52023-02-10
The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references. Flow configurations that include the ExtractCCDAAttributes Processor are vulnerable to malicious XML documents that …
- CVE-2023-23595HIGHCVSS 7.5EG 7.52023-01-15
BlueCat Device Registration Portal 2.2 allows XXE attacks that exfiltrate single-line files. A single-line file might contain credentials, such as "machine example.com login daniel password qwerty" in the documentation example for the .net…
- CVE-2023-23926MEDIUMCVSS 5.9EG 5.92023-02-16
APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j. An XML External Entity (XXE) vulnerability found in the apoc.import.graphml procedure of APOC core plugin prior to version 5.5.0 and 4.4.0.14 (4.4 branch) in Neo4j graph d…
- CVE-2023-24187HIGHCVSS 7.8EG 7.82023-02-14
An XML External Entity (XXE) vulnerability in ureport v2.2.9 allows attackers to execute arbitrary code via uploading a crafted XML file to /ureport/designer/saveReportFile.
- CVE-2023-24189CRITICALCVSS 9.8EG 9.82023-02-24
An XML External Entity (XXE) vulnerability in urule v2.1.7 allows attackers to execute arbitrary code via uploading a crafted XML file to /urule/common/saveFile.
- CVE-2023-24323HIGHCVSS 8.8EG 8.82023-02-09
Mojoportal v2.7 was discovered to contain an authenticated XML external entity (XXE) injection vulnerability.
- CVE-2023-24429CRITICALCVSS 9.8EG 9.82023-01-26
Jenkins Semantic Versioning Plugin 1.14 and earlier does not restrict execution of an controller/agent message to agents, and implements no limitations about the file path that can be parsed, allowing attackers able to control agent proces…
- CVE-2023-24430CRITICALCVSS 9.8EG 9.82023-01-26
Jenkins Semantic Versioning Plugin 1.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2023-24441CRITICALCVSS 9.8EG 9.82023-01-26
Jenkins MSTest Plugin 1.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2023-24443CRITICALCVSS 9.8EG 9.82023-01-26
Jenkins TestComplete support Plugin 2.8.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2023-24466HIGHCVSS 7.5EG 7.52024-11-22
Possible XML External Entity Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0200.
- CVE-2023-24470CRITICALCVSS 9.1EG 9.12023-06-13
Potential XML External Entity Injection in ArcSight Logger versions prior to 7.3.0.
- CVE-2023-24620MEDIUMCVSS 5.5EG 5.52023-08-25
An issue was discovered in Esoteric YamlBeans through 1.15. A crafted YAML document is able perform am XML Entity Expansion attack against YamlBeans YamlReader. By exploiting the Anchor feature in YAML, it is possible to generate a small Y…
- CVE-2023-25926MEDIUMCVSS 5.5EG 5.52024-02-29
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive inf…
- CVE-2023-25955MEDIUMCVSS 5.5EG 5.52023-04-11
National land numerical information data conversion tool all versions improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the PC may be accessed by an attacker.
- CVE-2023-26043MEDIUMCVSS 6.5EG 6.52023-02-27
GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. GeoNode is vulnerable to an XML External Entity (XXE) injection in the style upload functionality of GeoServer leading to …
- CVE-2023-26057MEDIUMCVSS 6.5EG 6.52023-04-25
An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to the Configuration Dashboard page. Input validation and a proper XML parser configuration are missing. For an external attacker, it is very difficult to exp…
- CVE-2023-26058MEDIUMCVSS 6.5EG 6.52023-04-25
An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to a Performance Manager page. Input validation and a proper XML parser configuration are missing. For an external attacker, it is very difficult to exploit t…
- CVE-2023-26263MEDIUMCVSS 5.5EG 5.52023-04-13
All versions of Talend Data Catalog before 8.0-20230110 are potentially vulnerable to XML External Entity (XXE) attacks in the /MIMBWebServices/license endpoint of the remote harvesting server.
Map vulnerabilities like CWE-611 to your infrastructure
EchelonGraph correlates every CVE — across CWE-611 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →