CWE-611— Improper Restriction of XML External Entity Reference (XXE)
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.— MITRE CWE catalog
1,275 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-611page 19 of 26
- CVE-2023-26264MEDIUMCVSS 5.5EG 5.52023-04-13
All versions of Talend Data Catalog before 8.0-20220907 are potentially vulnerable to XML External Entity (XXE) attacks in the license parsing code.
- CVE-2023-26267MEDIUMCVSS 6.5EG 6.52023-02-21
php-saml-sp before 1.1.1 and 2.x before 2.1.1 allows reading arbitrary files as the webserver user because resolving XML external entities was silently enabled via \LIBXML_DTDLOAD | \LIBXML_DTDATTR.
- CVE-2023-26461MEDIUMCVSS 6.8EG 6.82023-03-14
SAP NetWeaver allows (SAP Enterprise Portal) - version 7.50, allows an authenticated attacker with sufficient privileges to access the XML parser which can submit a crafted XML file which when parsed will enable them to access but not modi…
- CVE-2023-26999CRITICALCVSS 9.8EG 9.82024-01-09
An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted file.
- CVE-2023-27476HIGHCVSS 8.2EG 8.22023-03-08
OWSLib is a Python package for client programming with Open Geospatial Consortium (OGC) web service interface standards, and their related content models. OWSLib's XML parser (which supports both `lxml` and `xml.etree`) does not disable en…
- CVE-2023-27480HIGHCVSS 7.7EG 7.72023-03-07
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with edit rights on a document can trigger an XAR import on a forged XAR file, leading to the ability to…
- CVE-2023-27527HIGHCVSS 7.5EG 7.52023-05-10
Shinseiyo Sogo Soft (7.9A) and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the PC may be accessed by an attacker.
- CVE-2023-27554MEDIUMCVSS 6.3EG 6.32023-05-11
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory res…
- CVE-2023-27652MEDIUMCVSS 5.5EG 5.52023-04-20
An issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges cause a denial of service via the update_info field of the _default_.xml file.
- CVE-2023-27874CRITICALCVSS 9.9EG 9.92023-03-21
IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands. IBM X-Force ID: 249845.
- CVE-2023-27876HIGHCVSS 7.1EG 7.12023-04-07
IBM TRIRIGA 4.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 2499…
- CVE-2023-28008HIGHCVSS 7.1EG 7.12023-04-26
HCL Workload Automation 9.4, 9.5, and 10.1 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resou…
- CVE-2023-28009MEDIUMCVSS 6.5EG 6.52023-04-26
HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
- CVE-2023-2806MEDIUMCVSS 5.5EG 5.52023-05-19
A vulnerability classified as problematic was found in Weaver e-cology up to 9.0. Affected by this vulnerability is the function RequestInfoByXml of the component API. The manipulation leads to xml external entity reference. The associated…
- CVE-2023-28150CRITICALCVSS 5.3EG 9.82023-03-24
An issue was discovered in Independentsoft JODF before 1.1.110. The API is prone to XML external entity (XXE) injection via a remote DTD in a DOCX file.
- CVE-2023-28151CRITICALCVSS 5.3EG 9.82023-03-24
An issue was discovered in Independentsoft JSpreadsheet before 1.1.110. The API is prone to XML external entity (XXE) injection via a remote DTD in a DOCX file.
- CVE-2023-28152CRITICALCVSS 5.3EG 9.82023-03-24
An issue was discovered in Independentsoft JWord before 1.1.110. The API is prone to XML external entity (XXE) injection via a remote DTD in a DOCX file.
- CVE-2023-28340MEDIUMCVSS 6.5EG 6.52023-04-11
Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.
- CVE-2023-28680HIGHCVSS 7.5EG 7.52023-04-02
Jenkins Crap4J Plugin 0.9 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2023-28681HIGHCVSS 8.2EG 8.22023-04-02
Jenkins Visual Studio Code Metrics Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2023-28682HIGHCVSS 8.2EG 8.22023-04-02
Jenkins Performance Publisher Plugin 8.09 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2023-28683HIGHCVSS 8.2EG 8.22023-04-02
Jenkins Phabricator Differential Plugin 2.1.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2023-28684HIGHCVSS 6.5EG 7.12023-04-02
Jenkins remote-jobs-view-plugin Plugin 0.0.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2023-28685HIGHCVSS 7.1EG 7.12023-03-22
Jenkins AbsInt a³ Plugin 1.1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2023-28828MEDIUMCVSS 5.9EG 5.92023-04-11
A vulnerability has been identified in Polarion ALM (All versions < V22R2). The application contains a XML External Entity Injection (XXE) vulnerability. This could allow an attacker to view files on the application server filesystem.
- CVE-2023-29443MEDIUMCVSS 4.9EG 4.92023-04-26
Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML…
- CVE-2023-29498MEDIUMCVSS 5.5EG 5.52023-06-13
Improper restriction of XML external entity reference (XXE) vulnerability exists in FRENIC RHC Loader v1.1.0.3 and earlier. If a user opens a specially crafted project file, sensitive information on the system where the affected product is…
- CVE-2023-30951MEDIUMCVSS 6.3EG 6.32023-08-03
The Foundry Magritte plugin rest-source was found to be vulnerable to an an XML external Entity attack (XXE).
- CVE-2023-3113HIGHCVSS 8.2EG 8.22023-06-26
An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read-only access to specific files.
- CVE-2023-32327HIGHCVSS 7.1EG 7.12024-02-03
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) is vulnerable to an XML External Entity Injection (XXE) attack when proc…
- CVE-2023-32567CRITICALCVSS 9.8EG 9.82023-08-10
Ivanti Avalanche decodeToMap XML External Entity Processing. Fixed in version 6.4.1.236
- CVE-2023-32635MEDIUMCVSS 5.5EG 5.52023-07-19
XBRL data create application version 7.0 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XBRL file, arbitrary files on the system may be read by an attacker.
- CVE-2023-32639MEDIUMCVSS 5.5EG 5.52023-07-25
Applicant Programme Ver.7.06 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.
- CVE-2023-32706HIGHCVSS 7.7EG 7.72023-06-01
On Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, an unauthenticated attacker can send specially-crafted messages to the XML parser within SAML authentication to cause a denial of service in the Splunk daemon.
- CVE-2023-3276HIGHCVSS 5.5EG 7.52023-06-15
A vulnerability, which was classified as problematic, has been found in Dromara HuTool up to 5.8.19. Affected by this issue is the function readBySax of the file XmlUtil.java of the component XML Parsing Module. The manipulation leads to x…
- CVE-2023-34411HIGHCVSS 7.5EG 7.52023-06-05
The xml-rs crate before 0.8.14 for Rust and Crab allows a denial of service (panic) via an invalid <! token (such as <!DOCTYPEs/%<!A nesting) in an XML document. The earliest affected version is 0.8.9.
- CVE-2023-35389MEDIUMCVSS 6.5EG 6.52023-08-08
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
- CVE-2023-35786MEDIUMCVSS 4.9EG 4.92023-07-05
Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files.
- CVE-2023-35892HIGHCVSS 7.1EG 7.12023-09-05
IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consu…
- CVE-2023-36419HIGHCVSS 8.8EG 8.82023-10-10
Azure HDInsight Apache Oozie Workflow Scheduler XXE Elevation of Privilege Vulnerability
- CVE-2023-37200MEDIUMCVSS 5.5EG 5.52023-07-12
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause loss of confidentiality when replacing a project file on the local filesystem and after manual restart of the server.
- CVE-2023-37233HIGHCVSS 8.8EG 8.82024-09-10
Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks.
- CVE-2023-37364CRITICALCVSS 9.1EG 9.12023-08-03
In WS-Inc J WBEM Server 4.7.4 before 4.7.5, the CIM-XML protocol adapter does not disable entity resolution. This allows context-dependent attackers to read arbitrary files or cause a denial of service, a similar issue to CVE-2013-4152.
- CVE-2023-37497HIGHCVSS 8.1EG 8.12023-08-03
The Unica application exposes an API which accepts arbitrary XML input. By manipulating the given XML, an authenticated attacker with certain rights can successfully perform XML External Entity attacks (XXE) against the backend service.
- CVE-2023-37942MEDIUMCVSS 6.5EG 6.52023-07-12
Jenkins External Monitor Job Type Plugin 206.v9a_94ff0b_4a_10 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2023-3823HIGHCVSS 8.6EG 8.62023-08-11
In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state is assumed to be unc…
- CVE-2023-38343HIGHCVSS 7.5EG 7.52023-09-21
An XXE (XML external entity injection) vulnerability exists in the CSEP component of Ivanti Endpoint Manager before 2022 SU4. External entity references are enabled in the XML parser configuration. Exploitation of this vulnerability can le…
- CVE-2023-38490MEDIUMCVSS 6.8EG 6.82023-07-27
Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 only affects Kirby sites that use the `Xml` data handler (e.g. `Data::decode($string, 'xml')`) or the `Xml::parse()` m…
- CVE-2023-38693CRITICALCVSS 9.8EG 9.82025-03-05
Lucee Server (or simply Lucee) is a dynamic, Java based, tag and scripting language used for rapid web application development. The Lucee REST endpoint is vulnerable to RCE via an XML XXE attack. This vulnerability is fixed in Lucee 5.4.3.…
- CVE-2023-3892MEDIUMCVSS 5.6EG 5.62023-09-19
Improper Restriction of XML External Entity Reference vulnerability in MIM Assistant and Client DICOM RTst Loading modules allows XML Entity Linking / XML External Entities Blowup. In order to take advantage of this vulnerability, an a…
Map vulnerabilities like CWE-611 to your infrastructure
EchelonGraph correlates every CVE — across CWE-611 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →