CWE-611— Improper Restriction of XML External Entity Reference (XXE)
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.— MITRE CWE catalog
1,275 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-611page 23 of 26
- CVE-2024-6961MEDIUMCVSS 5.9EG 5.92024-07-21
RAIL documents are an XML-based format invented by Guardrails AI to enforce formatting checks on LLM outputs. Guardrails users that consume RAIL documents from external sources are vulnerable to XXE, which may cause leakage of internal fil…
- CVE-2024-7098CRITICALCVSS 9.8EG 9.82024-09-16
Improper Restriction of XML External Entity Reference vulnerability in SFS Consulting ww.Winsure allows XML Injection. This issue affects ww.Winsure: before 4.6.2.
- CVE-2024-8010LOWCVSS 3.5EG 3.52026-04-16
The component accepts XML input through the publisher without disabling external entity resolution. This allows malicious actors to submit a crafted XML payload that exploits the unescaped external entity references. By leveraging this vu…
- CVE-2024-8602MEDIUMCVSS 6.3EG 6.32024-10-14
When the XML is read from the codes in the PDF and parsed using a DocumentBuilder, the default settings of the DocumentBuilder allow for an XXE (XML External Entity) attack. Further information on this can be found on the website of the Op…
- CVE-2024-9044MEDIUMCVSS 4.6EG 4.62024-11-29
A XML External Entity (XXE) vulnerability has been identified in Easy Tax Client Software 2023 1.2 and earlier across multiple platforms, including Windows, Linux, and macOS.
- CVE-2025-0162HIGHCVSS 7.1EG 7.12025-03-07
IBM Aspera Shares 1.9.9 through 1.10.0 PL7 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to expose sensitive information or consume…
- CVE-2025-10091HIGHCVSS 7.3EG 7.32025-09-08
A vulnerability has been found in Jinher OA up to 1.2. This affects an unknown function of the file /c6/Jhsoft.Web.projectmanage/ProjectManage/XmlHttp.aspx/?Type=add of the component XML Handler. The manipulation leads to xml external enti…
- CVE-2025-10092HIGHCVSS 7.3EG 7.32025-09-08
A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown function of the file /c6/Jhsoft.Web.projectmanage/TaskManage/AddTask.aspx/?Type=add of the component XML Handler. The manipulation results in xml external entity ref…
- CVE-2025-10183CRITICALCVSS 9.1EG 9.12025-09-09
A blind XML External Entity (XXE) injection in the OpenMessaging webservice in TecCom TecConnect 4.1 allows an unauthenticated attacker to exfiltrate arbitrary files to an attacker-controlled server. TecConnect 4.1 is considered end-of-lif…
- CVE-2025-10713MEDIUMCVSS 6.5EG 6.52025-11-05
An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML parser. The application parses user-supplied XML without applying sufficient restrictions, allowing resolution of external…
- CVE-2025-10816HIGHCVSS 7.3EG 7.32025-09-22
A security flaw has been discovered in Jinher OA 2.0. This affects an unknown part of the file /c6/Jhsoft.Web.module/ToolBar/GetWordFileName.aspx/?text=GetUrl&style=add of the component XML Handler. Performing manipulation results in xml e…
- CVE-2025-11035MEDIUMCVSS 6.3EG 6.32025-09-26
A vulnerability was determined in Jinher OA 2.0. The impacted element is an unknown function of the file /c6/Jhsoft.Web.module/ToolBar/ManageWord.aspx/?text=GetUrl&style=1. This manipulation causes xml external entity reference. The attack…
- CVE-2025-11140HIGHCVSS 7.3EG 7.32025-09-29
A vulnerability was identified in Bjskzy Zhiyou ERP up to 11.0. Affected by this vulnerability is the function openForm of the component com.artery.richclient.RichClientService. Such manipulation of the argument contentString leads to xml …
- CVE-2025-11341HIGHCVSS 7.3EG 7.32025-10-06
A security flaw has been discovered in Jinher OA up to 2.0. This affects an unknown function of the file /c6/Jhsoft.Web.module/eformaspx/WebDesign.aspx/?type=SystemUserInfo&style=1. Performing manipulation results in xml external entity re…
- CVE-2025-11700HIGHCVSS 7.5EG 7.52025-11-12
N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure
- CVE-2025-1225MEDIUMCVSS 6.3EG 6.32025-02-12
A vulnerability, which was classified as problematic, has been found in ywoa up to 2024.07.03. This issue affects the function extract of the file c-main/src/main/java/com/redmoon/weixin/aes/XMLParse.java of the component WXCallBack Interf…
- CVE-2025-12531HIGHCVSS 7.1EG 7.12025-11-03
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or cons…
- CVE-2025-13209MEDIUMCVSS 6.3EG 6.32025-11-15
A weakness has been identified in bestfeng oa_git_free up to 9.5. This affects the function updateWriteBack of the file yimioa-oa9.5\server\c-flow\src\main\java\com\cloudweb\oa\controller\WorkflowPredefineController.java. This manipulation…
- CVE-2025-14478HIGHCVSS 7.5EG 7.52026-01-17
The Demo Importer Plus plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in all versions up to, and including, 2.0.9 via the SVG file upload functionality. This makes it possible for authenticated attackers, with Au…
- CVE-2025-14543CRITICALCVSS 9.1EG 9.12026-04-30
Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows Serialized Data External Linking.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.…
- CVE-2025-15251MEDIUMCVSS 5.6EG 5.62025-12-30
A vulnerability was detected in beecue FastBee up to 2.1. Impacted is the function getRootElement of the file springboot/fastbee-server/sip-server/src/main/java/com/fastbee/sip/handler/req/ReqAbstractHandler.java of the component SIP Messa…
- CVE-2025-1781MEDIUMCVSS 6.5EG 6.52025-03-28
There is a XXE in W3CSS Validator versions before cssval-20250226 that allows an attacker to use specially-crafted XML objects to coerce server-side request forgery (SSRF). This could be exploited to read arbitrary local files if an att…
- CVE-2025-20369MEDIUMCVSS 4.6EG 4.62025-10-01
In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a low privilege user that does not hold the "admin" or "power" Splunk roles could perform an…
- CVE-2025-2070MEDIUMCVSS 5.0EG 5.02025-04-25
An improper XML parsing vulnerability was reported in the FileZ client that could allow arbitrary file reads on the system if a crafted url is visited by a local user.
- CVE-2025-22478HIGHCVSS 8.1EG 8.12025-05-06
Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vuln…
- CVE-2025-23195HIGHCVSS 7.5EG 7.52025-01-21
An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie project, allowing an attacker to inject malicious XML entities. This vulnerability occurs due to insecure parsing of XML input using the `DocumentBuilderFactory` clas…
- CVE-2025-2365MEDIUMCVSS 6.3EG 6.32025-03-17
A vulnerability, which was classified as problematic, has been found in crmeb_java up to 1.3.4. Affected by this issue is the function webHook of the file WeChatMessageController.java. The manipulation leads to xml external entity referenc…
- CVE-2025-24521MEDIUMCVSS 4.9EG 4.92025-03-05
External XML entity injection allows arbitrary download of files. The score without least privilege principle violation is as calculated below. In combination with other issues it may facilitate further compromise of the device. Remedia…
- CVE-2025-24910MEDIUMCVSS 4.9EG 4.92025-04-16
Overview XML documents optionally contain a Document Type Definition (DTD), which, among other features, enables the definition of XML entities. It is possible to define an entity by providing a substitution string in the form of…
- CVE-2025-24911MEDIUMCVSS 4.9EG 4.92025-04-16
Overview XML documents optionally contain a Document Type Definition (DTD), which, among other features, enables the definition of XML entities. It is possible to define an entity by providing a substitution string in the form of…
- CVE-2025-25036MEDIUMCVSS 6.8EG 6.82025-03-21
Improper Restriction of XML External Entity Reference vulnerability in Jalios JPlatform allows XML Injection.This issue affects all versions of JPlatform 10 before 10.0.8 (SP8).
- CVE-2025-26400MEDIUMCVSS 5.3EG 5.32025-07-29
SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosure. A valid, low-privilege access is required unless the attacker had access to the local s…
- CVE-2025-26484MEDIUMCVSS 5.5EG 5.52025-08-14
Dell CloudLink, versions 8.0 through 8.1.1, contains an Improper Restriction of XML External Entity Reference vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of s…
- CVE-2025-27136MEDIUMCVSS 5.5EG 5.52025-03-10
LocalS3 is an Amazon S3 mock service for testing and local development. Prior to version 1.21, the LocalS3 service's bucket creation endpoint is vulnerable to XML External Entity (XXE) injection. When processing the CreateBucketConfigurati…
- CVE-2025-27523HIGHCVSS 8.7EG 8.72025-05-15
XXE vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Device Manager: from 12-00 before 12-00-08, from 11-10 through 11-10-08, from 11-00 through 1…
- CVE-2025-2775CRITICALCVSS 9.3EG 9.3⚠ KEV2025-05-07
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.
- CVE-2025-2776CRITICALCVSS 9.3EG 9.3⚠ KEV2025-05-07
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.
- CVE-2025-2777CRITICALCVSS 9.3EG 9.32025-05-07
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality, allowing for administrator account takeover and file read primitives.
- CVE-2025-2905CRITICALCVSS 9.1EG 9.12025-05-05
Due to the improper configuration of XML parser, user-supplied XML is parsed without applying sufficient restrictions, enabling XML External Entity (XXE) resolution in multiple WSO2 Products. A successful XXE attack could allow a remote, …
- CVE-2025-29932MEDIUMCVSS 4.1EG 4.12025-03-25
In JetBrains GoLand before 2025.1 an XXE during debugging was possible
- CVE-2025-30018HIGHCVSS 8.6EG 8.62025-05-13
The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) allows an unauthenticated attacker to submit an application servlet request with a crafted XML file which when parsed, enables the attacker to access sensitive files an…
- CVE-2025-30220CRITICALCVSS 9.9EG 9.92025-06-10
GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent schema data structure is vulnerable to XML External Entity (XXE) exploit. This impacts wh…
- CVE-2025-31039CRITICALCVSS 9.1EG 9.12025-06-09
Improper Restriction of XML External Entity Reference vulnerability in pixelgrade Category Icon category-icon allows XML Entity Linking.This issue affects Category Icon: from n/a through <= 1.0.3.
- CVE-2025-31487HIGHCVSS 7.7EG 7.72025-04-03
The XWiki JIRA extension provides various integration points between XWiki and JIRA (macros, UI, CKEditor plugin). If the JIRA macro is installed, any logged in XWiki user could edit his/her user profile wiki page and use that JIRA macro, …
- CVE-2025-31497HIGHCVSS 7.5EG 7.52025-04-15
TEIGarage is a webservice and RESTful service to transform, convert and validate various formats, focussing on the TEI format. The Document Conversion Service contains a critical XML External Entity (XXE) Injection vulnerability in its doc…
- CVE-2025-32138MEDIUMCVSS 6.6EG 6.62025-04-04
Improper Restriction of XML External Entity Reference vulnerability in supsystic Easy Google Maps google-maps-easy allows XML Injection.This issue affects Easy Google Maps: from n/a through <= 1.11.18.
- CVE-2025-32406HIGHCVSS 8.6EG 8.62025-04-08
An XXE issue in the Director NBR component in NAKIVO Backup & Replication 10.3.x through 11.0.1 before 11.0.2 allows remote attackers fetch and parse the XML response.
- CVE-2025-3241MEDIUMCVSS 6.3EG 6.32025-04-04
A vulnerability, which was classified as problematic, was found in zhangyanbo2007 youkefu up to 4.2.0. This affects an unknown part of the file src/main/java/com/ukefu/webim/web/handler/admin/callcenter/CallCenterRouterController.java of t…
- CVE-2025-33121HIGHCVSS 7.1EG 7.12025-06-19
IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume mem…
- CVE-2025-34142MEDIUMCVSS 6.9EG 6.92025-07-22
An XML External Entity (XXE) injection vulnerability exists in ETQ Reliance on the CG (legacy) platform within the `/resources/sessions/sso` endpoint. The SAML authentication handler processes XML input without disabling external entity re…
Map vulnerabilities like CWE-611 to your infrastructure
EchelonGraph correlates every CVE — across CWE-611 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →