CWE-611— Improper Restriction of XML External Entity Reference (XXE)
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.— MITRE CWE catalog
1,275 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-611page 20 of 26
- CVE-2023-39472MEDIUMCVSS 6.5EG 6.52024-05-03
Inductive Automation Ignition SimpleXMLReader XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Inductive Automati…
- CVE-2023-40239HIGHCVSS 7.5EG 7.52023-09-01
Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model …
- CVE-2023-40503HIGHCVSS 7.5EG 7.52024-05-03
LG Simple Editor saveXmlFile XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG Simple Editor. Authentication is…
- CVE-2023-40506HIGHCVSS 7.5EG 7.52024-05-03
LG Simple Editor copyContent XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG Simple Editor. Authentication is…
- CVE-2023-40507HIGHCVSS 7.5EG 7.52024-05-03
LG Simple Editor copyContent XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG Simple Editor. Authentication is…
- CVE-2023-41034CRITICALCVSS 9.8EG 9.82023-08-31
Eclipse Leshan is a device management server and client Java implementation. In affected versions DDFFileParser` and `DefaultDDFFileValidator` (and so `ObjectLoader`) are vulnerable to `XXE Attacks`. A DDF file is a LWM2M format used to st…
- CVE-2023-41365MEDIUMCVSS 4.3EG 4.32023-10-10
SAP Business One (B1i) - version 10.0, allows an authorized attacker to retrieve the details stack trace of the fault message to conduct the XXE injection, which will lead to information disclosure. After successful exploitation, an attack…
- CVE-2023-41369MEDIUMCVSS 4.3EG 4.32023-09-12
The Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, 107, 108, allows an attacker to upload the XML file as an attachment. When clicked on the XML file in the attachment section, the file get…
- CVE-2023-41932MEDIUMCVSS 6.5EG 6.52023-09-06
Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict 'timestamp' query parameters in multiple endpoints, allowing attackers with to delete attacker-specified directories on the Jenkins controller file …
- CVE-2023-41933HIGHCVSS 8.8EG 8.82023-09-06
Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2023-42035MEDIUMCVSS 6.5EG 6.52024-05-03
Visualware MyConnection Server doIForward XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Visualware MyConnectio…
- CVE-2023-42132MEDIUMCVSS 5.5EG 5.52023-10-02
FD Application Apr. 2022 Edition (Version 9.01) and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.
- CVE-2023-4218MEDIUMCVSS 5.0EG 5.02023-11-09
In Eclipse IDE versions < 2023-09 (4.29) some files with xml content are parsed vulnerable against all sorts of XXE attacks. The user just needs to open any evil project or update an open project with a vulnerable file (for example for rev…
- CVE-2023-42344HIGHCVSS 7.3EG 7.32026-05-08
Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/query XXE attack on a Chemistry servlet.
- CVE-2023-42346HIGHCVSS 7.5EG 7.52026-05-08
Alkacon OpenCms before 16 allows XXE when the <!DOCTYPE> refers to an external host.
- CVE-2023-42445MEDIUMCVSS 5.3EG 5.32023-10-06
Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, when Gradle parses XML files, resolving XML external entities is not disabled. Combined with an Out Of Band XXE attack (OOB-…
- CVE-2023-43067MEDIUMCVSS 6.5EG 6.52023-10-23
Dell Unity prior to 5.3 contains an XML External Entity injection vulnerability. An XXE attack could potentially exploit this vulnerability disclosing local files in the file system.
- CVE-2023-43624MEDIUMCVSS 5.5EG 5.52023-10-23
CX-Designer Ver.3.740 and earlier (included in CX-One CXONE-AL[][]D-V4) contains an improper restriction of XML external entity reference (XXE) vulnerability. If a user opens a specially crafted project file created by an attacker, sensit…
- CVE-2023-44412CRITICALCVSS 8.2EG 9.02024-05-03
D-Link D-View addDv7Probe XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of D-Link D-View. Authentication is not r…
- CVE-2023-45139HIGHCVSS 7.5EG 7.52024-01-10
fontTools is a library for manipulating fonts, written in Python. The subsetting module has a XML External Entity Injection (XXE) vulnerability which allows an attacker to resolve arbitrary entities when a candidate font (OT-SVG fonts), wh…
- CVE-2023-45192HIGHCVSS 8.2EG 8.22024-06-06
IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information …
- CVE-2023-4554MEDIUMCVSS 4.9EG 4.92024-01-29
Improper Restriction of XML External Entity Reference vulnerability in OpenText AppBuilder on Windows, Linux allows Server Side Request Forgery, Probe System Files. AppBuilder's XML processor is vulnerable to XML External Entity Processin…
- CVE-2023-45612CRITICALCVSS 9.8EG 9.82023-10-09
In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE
- CVE-2023-45727CRITICALCVSS 7.5EG 9.0⚠ KEV2023-10-18
Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and earlier allow a remote unauthenticated attacker to conduct XML External Entity (XXE) attack…
- CVE-2023-46265CRITICALCVSS 9.8EG 9.82023-12-19
An unauthenticated could abuse a XXE vulnerability in the Smart Device Server to leak data or perform a Server-Side Request Forgery (SSRF).
- CVE-2023-46502CRITICALCVSS 9.8EG 9.82023-10-30
An issue in openCRX v.5.2.2 allows a remote attacker to read internal files and execute server side request forgery attack via insecure DocumentBuilderFactory.
- CVE-2023-46590HIGHCVSS 7.5EG 7.52023-11-14
A vulnerability has been identified in Siemens OPC UA Modelling Editor (SiOME) (All versions < V2.8). Affected products suffer from a XML external entity (XXE) injection vulnerability. This vulnerability could allow an attacker to interfer…
- CVE-2023-46802MEDIUMCVSS 5.5EG 5.52023-11-06
e-Tax software Version3.0.10 and earlier improperly restricts XML external entity references (XXE) due to the configuration of the embedded XML parser. By processing a specially crafted XML file, arbitrary files on the system may be read b…
- CVE-2023-47160HIGHCVSS 8.2EG 8.22025-02-19
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive…
- CVE-2023-48362HIGHCVSS 8.8EG 8.82024-07-24
XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands via a malicious XML file. Users are recommended to upgrade to version 1.21.2, which fixes th…
- CVE-2023-49110HIGHCVSS 7.2EG 7.22024-06-20
When the Kiuwan Local Analyzer uploads the scan results to the Kiuwan SAST web application (either on-premises or cloud/SaaS solution), the transmitted data consists of a ZIP archive containing several files, some of them in the XML fil…
- CVE-2023-49234MEDIUMCVSS 6.3EG 6.32024-03-29
An XML external entity (XXE) vulnerability was found in Stilog Visual Planning 8. It allows an authenticated attacker to access local server files and exfiltrate data to an external server.
- CVE-2023-49656CRITICALCVSS 9.8EG 9.82023-11-29
Jenkins MATLAB Plugin 2.11.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2023-49733CRITICALCVSS 9.8EG 9.82023-11-30
Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue.
- CVE-2023-50168HIGHCVSS 7.7EG 7.72024-03-14
Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.
- CVE-2023-50304HIGHCVSS 7.1EG 7.12024-07-18
IBM Engineering Requirements Management DOORS Web Access 9.7.2.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or…
- CVE-2023-50380MEDIUMCVSS 6.5EG 6.52024-02-27
XML External Entity injection in apache ambari versions <= 2.7.7, Users are recommended to upgrade to version 2.7.8, which fixes this issue. More Details: Oozie Workflow Scheduler had a vulnerability that allowed for root-level file rea…
- CVE-2023-5136MEDIUMCVSS 5.5EG 5.52023-11-08
An incorrect permission assignment in the TopoGrafix DataPlugin for GPX could result in information disclosure. An attacker could exploit this vulnerability by getting a user to open a specially crafted data file.
- CVE-2023-51591HIGHCVSS 7.5EG 7.52024-05-03
Voltronic Power ViewPower Pro doDocument XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Voltronic Power ViewPow…
- CVE-2023-51600MEDIUMCVSS 6.5EG 6.52024-05-03
Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Honeywell Saia PG5 Controls Su…
- CVE-2023-51601MEDIUMCVSS 6.5EG 6.52024-05-03
Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Honeywell Saia PG5 Controls Su…
- CVE-2023-51602MEDIUMCVSS 6.5EG 6.52024-05-03
Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Honeywell Saia PG5 Controls Su…
- CVE-2023-51604MEDIUMCVSS 6.5EG 6.52024-05-03
Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Honeywell Saia PG5 Controls Su…
- CVE-2023-51605MEDIUMCVSS 6.5EG 6.52024-05-03
Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Honeywell Saia PG5 Controls Su…
- CVE-2023-52239MEDIUMCVSS 6.5EG 6.52024-02-06
The XML parser in Magic xpi Integration Platform 4.13.4 allows XXE attacks, e.g., via onItemImport.
- CVE-2023-52252CRITICALCVSS 9.8EG 9.82023-12-30
Unified Remote 3.13.0 allows remote attackers to execute arbitrary Lua code because of a wildcarded Access-Control-Allow-Origin for the Remote upload endpoint.
- CVE-2023-6147MEDIUMCVSS 6.5EG 6.52024-01-09
Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a security flaw, which was missing a permission check while performing a connectivity check to Qualys Cloud Services. This al…
- CVE-2023-6149MEDIUMCVSS 6.5EG 6.52024-01-09
Qualys Jenkins Plugin for WAS prior to version and including 2.0.11 was identified to be affected by a security flaw, which was missing a permission check while performing a connectivity check to Qualys Cloud Services. This allowed any us…
- CVE-2023-6194HIGHCVSS 7.1EG 7.12023-12-11
In Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered to prohibit document type definition (DTD) references to external entities. This means that if a user chooses to use a malicious report definit…
- CVE-2023-6280HIGHCVSS 7.5EG 7.52023-12-19
An XXE (XML External Entity) vulnerability has been detected in 52North WPS affecting versions prior to 4.0.0-beta.11. This vulnerability allows the use of external entities in its WebProcessingService servlet for an attacker to retrieve f…
Map vulnerabilities like CWE-611 to your infrastructure
EchelonGraph correlates every CVE — across CWE-611 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →