CWE-611— Improper Restriction of XML External Entity Reference (XXE)
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.— MITRE CWE catalog
1,331 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-611page 27 of 27
- CVE-2026-58248MEDIUMCVSS 6.5EG 6.52026-08-11
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a specially crafted spreadsheet file containing malicious external references. When the file is processed as a data source, th…
- CVE-2026-6501MEDIUMCVSS 5.3EG 5.32026-05-04
Improper restriction of XML external entity reference vulnerability in ILM Informatique jOpenDocument allows Data Serialization External Entities Blowup. This issue affects jOpenDocument: 1.5.
- CVE-2026-65432HIGHCVSS 7.5EG 7.52026-08-06
Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any <wsdl:import> or <xsd:import> referenced from that top-level WSDL is handed off to WSDL4J, which does not…
- CVE-2026-6653CRITICALCVSS 9.8EG 9.82026-06-22
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.
- CVE-2026-67268MEDIUMCVSS 6.5EG 6.52026-08-19
Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevat…
- CVE-2026-6807MEDIUMCVSS 5.5EG 5.52026-04-28
A vulnerability in GRASSMARLIN v3.2.1 allows crafted session data to trigger improper handling of XML input, which may result in unintended exposure of sensitive information. The flaw stems from insufficient hardening of the XML parsing…
- CVE-2026-69101HIGHCVSS 7.7EG 7.72026-08-14
Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to perform server-side request forgery and out-of-band file exfiltration by supplying a crafted taskScript payload to the…
- CVE-2026-70423MEDIUMCVSS 6.5EG 6.52026-08-19
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Inf…
- CVE-2026-70448HIGHCVSS 7.1EG 7.12026-08-05
Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when processing Ivy report files.
- CVE-2026-71375HIGHCVSS 7.4EG 7.42026-09-08
Improper restriction of XML external entity reference vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-…
- CVE-2026-73235MEDIUMCVSS 6.1EG 6.12026-08-11
FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the Xerces SAX2 XMLReader constructed in src/Base/Reader.cpp by Base::XMLReader::XMLReader() parses attacker-controlled Document.xml from a crafted .FCS…
- CVE-2026-75055MEDIUMCVSS 5.5EG 5.52026-08-17
In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE
- CVE-2026-75058MEDIUMCVSS 5.5EG 5.52026-08-17
In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers
- CVE-2026-76427MEDIUMCVSS 4.9EG 4.92026-09-16
A vulnerability in the offline profiler feed service of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files that are stored on an affected device. This vulnerability is due to the parsing of attacker-controll…
- CVE-2026-76446MEDIUMCVSS 4.9EG 4.92026-09-16
A vulnerability in an API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read specific files on the underlying operating system of an affected device. This vulnerability is due to improper restricti…
- CVE-2026-76572MEDIUMCVSS 4.7EG 4.72026-08-19
A vulnerability was detected in pkp pkp-lib up to 3.3.0-22/3.4.0-10/3.5.0-4. The affected element is the function _transformPHP of the file classes/xslt/XSLTransformer.php. The manipulation results in xml external entity reference. The att…
- CVE-2026-76958HIGHCVSS 8.5EG 8.52026-09-08
SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML payloads containing malicious external en…
- CVE-2026-78224HIGHCVSS 8.2EG 8.22026-09-11
The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, so XXE injection can allow data exfiltration and denial-of-service attacks.
- CVE-2026-79572HIGHCVSS 7.5EG 7.52026-09-08
An XXE (XML External Entity) vulnerability in the level-rule module of Distribution Management v1.0.0 allows attackers to read sensitive files, scan internal networks, or launch server attacks via supplying a crafted XML payload.
- CVE-2026-8045MEDIUMCVSS 6.5EG 6.52026-06-09
CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits crafted XML payloads to…
- CVE-2026-81832HIGHCVSS 7.7EG 7.72026-09-04
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 SAP Adapter is vulnerable to an XML external entity (XXE) attack.
- CVE-2026-82525MEDIUMCVSS 5.5EG 5.52026-09-03
Exterro FTK Imager before 8.3 contains an XML external entity (XXE) injection vulnerability that allows attackers to read arbitrary files from the host filesystem by embedding malicious external entity references and attacker-controlled XS…
- CVE-2026-82578HIGHCVSS 7.5EG 7.52026-09-11
When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a default XPath/JAXP setup with no entity restrictions, so XXE injection can allow data exfiltration and denial-of-service attacks.
- CVE-2026-82880HIGHCVSS 7.5EG 7.52026-08-31
YaCy Search Server through 1.941 contains an XML external entity injection vulnerability in SVG, FreeMind, and OpenSearch parsers that fail to disable external entity resolution. Attackers can publish malicious documents with DOCTYPE decla…
- CVE-2026-82918MEDIUMCVSS 5.5EG 5.52026-09-03
XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporation improperly restrict XML external entity references. If a user opens a specially crafted setting file, the sensitive information stored in the system where XG VisionT…
- CVE-2026-8396HIGHCVSS 7.5EG 7.52026-07-17
Improper restriction of XML external entity reference vulnerability in Netcad Software Inc. NetGIS allows Serialized Data External Linking. This issue affects NetGIS: from 5.0.66 before 7.2.2.
- CVE-2026-84941MEDIUMCVSS 6.9EG 6.92026-09-10
An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of us…
- CVE-2026-89212HIGHCVSS 8.6EG 8.62026-09-11
A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, 2025.1.1, and all versions before 2024.1.6…
- CVE-2026-89260HIGHCVSS 7.5EG 7.52026-09-11
MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at POST /wechat/wechatCheck. The WechatRestApi.index() method passes the raw request body to SignUtil.xmlToMap(), which uses an unh…
- CVE-2026-91197MEDIUMCVSS 6.5EG 6.52026-09-14
Flowable flowable-engine through 8.0.0 contains an XML external entity injection vulnerability in ProcessDiagramLayoutFactory.parseXml() that fails to disable external entity resolution when parsing deployed BPMN resources. Attackers with …
- CVE-2026-94108MEDIUMCVSS 6.5EG 6.52026-09-20
getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array helper function that fails to properly disable entity loading on PHP before 8.0. Attackers can craft malicious XML metadata in media files to di…
Map vulnerabilities like CWE-611 to your infrastructure
EchelonGraph correlates every CVE — across CWE-611 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →