CWE-611— Improper Restriction of XML External Entity Reference (XXE)
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.— MITRE CWE catalog
1,275 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-611page 22 of 26
- CVE-2024-40896CRITICALCVSS 9.1EG 9.12024-12-23
In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE at…
- CVE-2024-4184HIGHCVSS 8.0EG 8.02024-10-16
Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.
- CVE-2024-4189HIGHCVSS 8.0EG 8.02024-10-16
Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.
- CVE-2024-42185LOWCVSS 2.5EG 2.52025-01-23
BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML injection attacks. This allows an attacker to exploit this vulnerability by injecting malicious XML content, which can lead to various issues i…
- CVE-2024-4357MEDIUMCVSS 6.5EG 6.52024-05-15
An information disclosure vulnerability exists in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, allows low-privilege attacker to read systems file via XML External Entity Processing.
- CVE-2024-45048HIGHCVSS 8.8EG 8.82024-08-28
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions are subject to a bypassing of a filter which allows for an XXE-attack. This in turn allows attacker to obtain contents of local files, even i…
- CVE-2024-45072MEDIUMCVSS 5.5EG 5.52024-10-16
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory reso…
- CVE-2024-45086MEDIUMCVSS 5.5EG 5.52024-11-04
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory reso…
- CVE-2024-45293HIGHCVSS 7.5EG 7.52024-10-07
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The security scanner responsible for preventing XXE attacks in the XLSX reader can be bypassed by slightly modifying the XML structure, utilizing white-spaces.…
- CVE-2024-45294HIGHCVSS 8.6EG 8.62024-09-06
The HL7 FHIR Core Artifacts repository provides the java core object handling code, with utilities (including validator), for the Fast Healthcare Interoperability Resources (FHIR) specification. Prior to version 6.3.23, XSLT transforms per…
- CVE-2024-45490CRITICALCVSS 9.8EG 9.82024-08-30
An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.
- CVE-2024-45745MEDIUMCVSS 5.0EG 5.02024-09-27
TopQuadrant TopBraid EDG before version 8.0.1 allows an authenticated attacker to upload an XML DTD file and execute JavaScript to read local files or access URLs (XXE). Fixed in 8.0.1 (bug fix: TBS-6721).
- CVE-2024-46455CRITICALCVSS 9.8EG 9.82024-12-09
unstructured v.0.14.2 and before is vulnerable to XML External Entity (XXE) via the XMLParser.
- CVE-2024-46602HIGHCVSS 7.5EG 7.52025-01-07
An issue was discovered in Elspec G5 digital fault recorder version 1.2.1.12 and earlier. An XML External Entity (XXE) vulnerability may allow an attacker to cause a Denial of Service (DoS) via a crafted XML payload.
- CVE-2024-46603HIGHCVSS 7.5EG 7.52025-01-07
An XML External Entity (XXE) vulnerability in Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 allows attackers to cause a Denial of Service (DoS) via a crafted XML payload.
- CVE-2024-4690HIGHCVSS 8.0EG 8.02024-10-16
Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.
- CVE-2024-46984HIGHCVSS 8.6EG 8.62024-09-19
The reference validator is a tool to perform advanced validation of FHIR resources for TI applications and interoperability standards. The profile location routine in the referencevalidator commons package is vulnerable to `XML External En…
- CVE-2024-46985HIGHCVSS 7.5EG 7.52024-09-23
DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, there is an XML external entity injection vulnerability in the static resource upload interface of DataEase. An attacker can construct a payload to imple…
- CVE-2024-47582MEDIUMCVSS 5.3EG 5.32024-12-10
Due to missing validation of XML input, an unauthenticated attacker could send malicious input to an endpoint which leads to XML Entity Expansion attack. This causes limited impact on availability of the application.
- CVE-2024-47873HIGHCVSS 7.5EG 7.52024-11-18
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. The XmlScanner class has a scan method which should prevent XXE attacks. However, prior to versions 1.9.4, 2.1.3, 2.3.2, and 3.4.0, the regexes used in the `scan` m…
- CVE-2024-48917HIGHCVSS 7.5EG 7.52024-11-18
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. The `XmlScanner` class has a scan method which should prevent XXE attacks. However, in a bypass of the previously reported `CVE-2024-47873`, the regexes from the `f…
- CVE-2024-49064MEDIUMCVSS 6.5EG 6.52024-12-12
Microsoft SharePoint Information Disclosure Vulnerability
- CVE-2024-49352HIGHCVSS 7.1EG 7.12025-02-05
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerabi…
- CVE-2024-49535MEDIUMCVSS 6.3EG 6.32024-12-10
Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that allows an attacker to provide mali…
- CVE-2024-49704MEDIUMCVSS 5.5EG 5.52024-12-10
A vulnerability has been identified in COMOS V10.3 (All versions < V10.3.3.5.8), COMOS V10.4.0 (All versions), COMOS V10.4.1 (All versions), COMOS V10.4.2 (All versions), COMOS V10.4.3 (All versions < V10.4.3.0.47), COMOS V10.4.4 (All vers…
- CVE-2024-49781HIGHCVSS 7.1EG 7.12025-02-20
IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memo…
- CVE-2024-50442MEDIUMCVSS 6.5EG 6.52024-10-28
Improper Restriction of XML External Entity Reference vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows XML Injection.This issue affects Royal Elementor Addons: from n/a through <= 1.3.980.
- CVE-2024-50848MEDIUMCVSS 6.5EG 6.52024-11-18
An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute arbitrary commands via supplying a crafted .tmx file.
- CVE-2024-51132CRITICALCVSS 9.8EG 9.82024-11-05
An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.
- CVE-2024-51136CRITICALCVSS 9.8EG 9.82024-11-04
An XML External Entity (XXE) vulnerability in Dmoz2CSV in openimaj v1.3.10 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted XML file.
- CVE-2024-51445MEDIUMCVSS 6.5EG 6.52025-05-13
A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The affected application contains a XML External Entity Injection (XXE) vulnerability in the docx import feature. This could all…
- CVE-2024-52007HIGHCVSS 8.6EG 8.62024-11-08
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. XSLT parsing performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious D…
- CVE-2024-52596HIGHCVSS 8.8EG 8.82024-12-02
SimpleSAMLphp xml-common is a common classes for handling XML-structures. When loading an (untrusted) XML document, for example the SAMLResponse, it's possible to induce an XXE. This vulnerability is fixed in 1.19.0.
- CVE-2024-52800LOWCVSS 2.3EG 2.32024-11-29
veraPDF is an open source PDF/A validation library. Executing policy checks using custom schematron files via the CLI invokes an XSL transformation that may theoretically lead to a remote code execution (RCE) vulnerability. This doesn't af…
- CVE-2024-52806HIGHCVSS 8.3EG 8.32024-12-02
SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. When loading an (untrusted) XML document, for example the SAMLResponse, it's possible to induce an XXE. This vulnerability is fixed in 4.6.14 and 5.0.0-alpha.18.
- CVE-2024-52807HIGHCVSS 8.6EG 8.62025-01-24
The HL7 FHIR IG publisher is a tool to take a set of inputs and create a standard FHIR IG. Prior to version 1.7.4, XSLT transforms performed by various components are vulnerable to XML external entity injections. A processed XML file with …
- CVE-2024-53674HIGHCVSS 7.3EG 7.82024-11-26
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.
- CVE-2024-53675CRITICALCVSS 7.3EG 9.02024-11-26
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.
- CVE-2024-54005MEDIUMCVSS 5.1EG 5.12024-12-10
A vulnerability has been identified in COMOS V10.3 (All versions < V10.3.3.5.8), COMOS V10.4.0 (All versions), COMOS V10.4.1 (All versions), COMOS V10.4.2 (All versions), COMOS V10.4.3 (All versions < V10.4.3.0.47), COMOS V10.4.4 (All vers…
- CVE-2024-54171HIGHCVSS 7.1EG 7.12025-02-06
IBM EntireX 11.1 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
- CVE-2024-55081CRITICALCVSS 9.8EG 9.82024-12-19
An XML External Entity (XXE) injection vulnerability in the component /datagrip/upload of Chat2DB v0.3.5 allows attackers to execute arbitrary code via supplying a crafted XML input.
- CVE-2024-55875CRITICALCVSS 9.8EG 9.82024-12-12
http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 6.50.0.0, there is a potential XXE (XML External Entity Injection) vulnerability when http4k handling malicious XML contents within requests, which might allow a…
- CVE-2024-55887HIGHCVSS 8.6EG 8.62024-12-13
Ucum-java is a FHIR Java library providing UCUM Services. In versions prior to 1.0.9, XML parsing performed by the UcumEssenceService is vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag could prod…
- CVE-2024-5625MEDIUMCVSS 6.5EG 6.52024-07-18
Improper Restriction of XML External Entity Reference vulnerability in PruvaSoft Informatics Apinizer Management Console allows Data Serialization External Entities Blowup. This issue affects Apinizer Management Console: before 2024.05.1.
- CVE-2024-56322HIGHCVSS 7.2EG 7.22025-01-03
GoCD is a continuous deliver server. GoCD versions 16.7.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse a hidden/unused configuration repository (pipelines as code) feature to allow XML External Entity (XXE) injection on the Go…
- CVE-2024-56324HIGHCVSS 7.1EG 7.12025-01-03
GoCD is a continuous deliver server. GoCD versions prior to 24.4.0 can allow GoCD "group admins" to abuse ability to edit the raw XML configuration for groups they administer to trigger XML External Entity (XXE) injection on the GoCD serve…
- CVE-2024-56356MEDIUMCVSS 5.9EG 5.92024-12-20
In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack
- CVE-2024-58335MEDIUMCVSS 5.0EG 5.02025-12-24
OpenXRechnungToolbox through 2024-10-05-3.0.0 before 6c50e89 allows XXE because the disallow-doctype-decl feature is not enabled in visualization/VisualizerImpl.java.
- CVE-2024-5919MEDIUMCVSS 6.5EG 6.52024-11-14
A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate arbitrary files from firewalls to an attacker controlled server. This attack requires net…
- CVE-2024-6893HIGHCVSS 7.5EG 7.62024-08-08
The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This allows an unauthenticated attacker to read local files, perform server-side request forgery, and overwhelm the web server …
Map vulnerabilities like CWE-611 to your infrastructure
EchelonGraph correlates every CVE — across CWE-611 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →