CWE-611— Improper Restriction of XML External Entity Reference (XXE)
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.— MITRE CWE catalog
1,275 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-611page 21 of 26
- CVE-2023-6721HIGHCVSS 7.5EG 8.32023-12-13
An XEE vulnerability has been found in Repox, which allows a remote attacker to interfere with the application's XML data processing in the fileupload function, resulting in interaction between the attacker and the server's file system.
- CVE-2023-6836HIGHCVSS 7.5EG 7.52023-12-15
Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely available but rarely used feature of XML parsers to access sensitive information.
- CVE-2023-7307HIGHCVSS 8.7EG 8.72025-08-27
Sangfor Behavior Management System (also referred to as DC Management System in Chinese-language documentation) contains an XML external entity (XXE) injection vulnerability in the /src/sangforindex endpoint. A remote unauthenticated attac…
- CVE-2024-10218CRITICALCVSS 9.2EG 9.22024-11-12
XSS Attack in mar.jar, Monitoring Archive Utility (MAR Utility), monitoringconsolecommon.jar in TIBCO Software Inc TIBCO Hawk and TIBCO Operational Intelligence
- CVE-2024-10839HIGHCVSS 8.5EG 8.52024-11-08
Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entity (XXE) in the Management option.
- CVE-2024-11622HIGHCVSS 7.3EG 7.32024-11-26
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.
- CVE-2024-1167MEDIUMCVSS 5.5EG 5.52024-02-01
When SEW-EURODRIVE MOVITOOLS MotionStudio processes XML information unrestricted file access can occur.
- CVE-2024-12298MEDIUMCVSS 5.5EG 5.52025-01-14
We found a vulnerability Improper Restriction of XML External Entity Reference (CWE-611) in NB-series NX-Designer. Attackers may be able to abuse this vulnerability to disclose confidential data on a computer.
- CVE-2024-12476HIGHCVSS 7.8EG 7.82025-01-17
CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure, impacts workstation integrity and potential remote code execution on the compromised computer, when specific craft…
- CVE-2024-13971HIGHCVSS 7.5EG 7.52026-04-30
Unauthenticated attackers can exploit a weakness in the XML parser functionality of Lobster_pro prior to version 4.12.6-GA. This allows them to obtain read access to files on the application server and adjacent network shares, and perform …
- CVE-2024-20531MEDIUMCVSS 5.5EG 5.52024-11-06
A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device and conduct a server-side request forgery (SSRF) attack through an affec…
- CVE-2024-21048MEDIUMCVSS 4.3EG 4.32024-04-16
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: XML input). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged att…
- CVE-2024-21082CRITICALCVSS 9.8EG 9.82024-04-16
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that are affected are 7.0.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with netw…
- CVE-2024-21255HIGHCVSS 8.8EG 8.82024-10-15
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: XMLPublisher). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows low privileged attacker …
- CVE-2024-21765MEDIUMCVSS 5.5EG 5.52024-01-24
Electronic Delivery Check System (Doboku) Ver.18.1.0 and earlier, Electronic Delivery Check System (Dentsu) Ver.12.1.0 and earlier, Electronic Delivery Check System (Kikai) Ver.10.1.0 and earlier, and Electronic delivery item Inspection Su…
- CVE-2024-21796MEDIUMCVSS 5.5EG 5.52024-01-24
Electronic Deliverables Creation Support Tool (Construction Edition) prior to Ver1.0.4 and Electronic Deliverables Creation Support Tool (Design & Survey Edition) prior to Ver1.0.4 improperly restrict XML external entity references (XXE). …
- CVE-2024-22024CRITICALCVSS 8.3EG 9.02024-02-13
An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authenticatio…
- CVE-2024-22218HIGHCVSS 8.8EG 8.82024-08-15
XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC versions up to 1.0.4 allows authenticated users to submit malicious XML via unspecified features which could lead to various actions such as acces…
- CVE-2024-22354HIGHCVSS 7.0EG 7.02024-04-17
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.5 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this…
- CVE-2024-22380MEDIUMCVSS 5.5EG 5.52024-01-24
Electronic Delivery Check System (Ministry of Agriculture, Forestry and Fisheries The Agriculture and Rural Development Project Version) March, Heisei 31 era edition Ver.14.0.001.002 and earlier improperly restricts XML external entity ref…
- CVE-2024-23525MEDIUMCVSS 6.5EG 6.52024-01-18
The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig.
- CVE-2024-2374HIGHCVSS 7.5EG 7.52026-04-16
The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the resolution of external entities. This omission allows malicious actors to craft XML payloads that exploit the parser's …
- CVE-2024-24743HIGHCVSS 8.6EG 8.62024-02-13
SAP NetWeaver AS Java (CAF - Guided Procedures) - version 7.50, allows an unauthenticated attacker to submit a malicious request with a crafted XML file over the network, which when parsed will enable him to access sensitive files and data…
- CVE-2024-25066MEDIUMCVSS 4.3EG 4.32025-02-17
RSA Authentication Manager before 8.7 SP2 Patch 1 allows XML External Entity (XXE) attacks via a license file, resulting in attacker-controlled files being stored on the product's server. Data exfiltration cannot occur.
- CVE-2024-25129LOWCVSS 2.7EG 2.72024-02-22
The CodeQL CLI repo holds binaries for the CodeQL command line interface (CLI). Prior to version 2.16.3, an XML parser used by the CodeQL CLI to read various auxiliary files is vulnerable to an XML External Entity attack. If a vulnerable v…
- CVE-2024-25606HIGHCVSS 8.0EG 8.02024-02-20
XXE vulnerability in Liferay Portal 7.2.0 through 7.4.3.7, and older unsupported versions, and Liferay DXP 7.4 before update 4, 7.3 before update 12, 7.2 before fix pack 20, and older unsupported versions allows attackers with permission t…
- CVE-2024-25971MEDIUMCVSS 5.5EG 5.52024-03-28
Dell PowerProtect Data Manager, version 19.15, contains an XML External Entity Injection vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to information disclosure, denial-of-service.
- CVE-2024-27266HIGHCVSS 8.2EG 8.22024-03-14
IBM Maximo Application Suite 7.6.1.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. …
- CVE-2024-28039MEDIUMCVSS 5.8EG 5.82024-03-18
Improper restriction of XML external entity references vulnerability exists in FitNesse all releases, which allows a remote unauthenticated attacker to obtain sensitive information, alter data, or cause a denial-of-service (DoS) condition.
- CVE-2024-28168HIGHCVSS 7.5EG 7.52024-10-09
Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: 2.9. Users are recommended to upgrade to version 2.10, which fixes the issue.
- CVE-2024-28198MEDIUMCVSS 4.6EG 4.62024-03-11
OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. By manually manipulating http requests when using the draw.io integration it is possible to read arbitrary files as the configur…
- CVE-2024-2826MEDIUMCVSS 6.3EG 6.32024-03-22
A vulnerability classified as problematic was found in lakernote EasyAdmin up to 20240315. This vulnerability affects unknown code of the file /ureport/designer/saveReportFile. The manipulation leads to xml external entity reference. The a…
- CVE-2024-29010HIGHCVSS 7.1EG 7.12024-05-01
The XML document processed in the GMS ECM URL endpoint is vulnerable to XML external entity (XXE) injection, potentially resulting in the disclosure of sensitive information. This issue affects GMS: 9.3.4 and earlier versions.
- CVE-2024-30043HIGHCVSS 6.5EG 7.62024-05-14
Microsoft SharePoint Server Information Disclosure Vulnerability
- CVE-2024-31139MEDIUMCVSS 5.9EG 5.92024-03-28
In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector
- CVE-2024-34102CRITICALCVSS 9.8EG 9.8⚠ KEV2024-06-13
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit…
- CVE-2024-34345HIGHCVSS 8.1EG 8.12024-05-14
The CycloneDX JavaScript library contains the core functionality of OWASP CycloneDX for JavaScript. In 6.7.0, XML External entity injections were possible, when running the provided XML Validator on arbitrary input. This issue was fixed in…
- CVE-2024-34711CRITICALCVSS 9.3EG 9.32025-06-10
GeoServer is an open source server that allows users to share and edit geospatial data. An improper URI validation vulnerability exists that enables an unauthorized attacker to perform XML External Entities (XEE) attack, then send GET requ…
- CVE-2024-3486HIGHCVSS 7.8EG 7.82024-05-15
XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to information disclosure and remote code execution.
- CVE-2024-36827HIGHCVSS 7.5EG 7.52024-06-07
An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of ebookmeta before v1.2.8 allows attackers to access sensitive information or cause a Denial of Service (DoS) via crafted XML input.
- CVE-2024-37388CRITICALCVSS 9.1EG 9.12024-06-07
An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of lxml before v4.9.1 allows attackers to access sensitive information or cause a Denial of Service (DoS) via crafted XML input.
- CVE-2024-37397HIGHCVSS 8.2EG 8.62024-09-12
An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to leak API secrets.
- CVE-2024-38374HIGHCVSS 7.5EG 7.52024-06-28
The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, validating, and parsing SBOMs. Before deserializing CycloneDX Bill of Materials in XML format, _cyclonedx-core-java_ leverage…
- CVE-2024-38653CRITICALCVSS 7.5EG 9.02024-08-14
XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.
- CVE-2024-3930MEDIUMCVSS 6.3EG 6.32024-07-30
In versions of Akana API Platform prior to 2024.1.0 a flaw resulting in XML External Entity (XXE) was discovered.
- CVE-2024-39586LOWCVSS 2.9EG 2.92024-10-09
Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high privileged attacker could potentially exploit this vulnerability, leading to information disclosure.
- CVE-2024-3969HIGHCVSS 7.8EG 7.82024-05-28
XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to remote code execution by parsing untrusted XML payload
- CVE-2024-39726HIGHCVSS 8.2EG 8.22024-11-15
IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive i…
- CVE-2024-39847HIGHCVSS 7.5EG 7.52026-04-30
Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GE…
- CVE-2024-40075MEDIUMCVSS 4.3EG 4.32024-07-22
Laravel v11.x was discovered to contain an XML External Entity (XXE) vulnerability.
Map vulnerabilities like CWE-611 to your infrastructure
EchelonGraph correlates every CVE — across CWE-611 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →