CWE-611— Improper Restriction of XML External Entity Reference (XXE)
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.— MITRE CWE catalog
1,275 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-611page 6 of 26
- CVE-2018-10600CRITICALCVSS 9.8EG 9.82018-07-24
SEL AcSELerator Architect version 2.2.24.0 and prior allows unsanitized input to be passed to the XML parser, which may allow disclosure and retrieval of arbitrary data, arbitrary code execution (in certain situations on specific platforms…
- CVE-2018-10613HIGHCVSS 7.5EG 7.52018-06-04
Multiple variants of XML External Entity (XXE) attacks may be used to exfiltrate data from the host Windows platform in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior.
- CVE-2018-10614HIGHCVSS 8.8EG 8.82018-10-09
An XXE vulnerability in LeviStudioU, Versions 1.8.29 and 1.8.44 can be exploited when the application processes specially crafted project XML files.
- CVE-2018-10653CRITICALCVSS 9.8EG 9.82018-05-23
There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
- CVE-2018-1077HIGHCVSS 7.5EG 7.52018-03-14
Spacewalk 2.6 contains an API which has an XXE flaw allowing for the disclosure of potentially sensitive information from the server.
- CVE-2018-10832MEDIUMCVSS 5.5EG 5.52018-05-11
ModbusPal 1.6b is vulnerable to an XML External Entity (XXE) attack. Projects are saved as .xmpp files and automations can be exported as .xmpa files, both XML-based, which are vulnerable to XXE injection. Sending a crafted .xmpp or .xmpa …
- CVE-2018-11048HIGHCVSS 8.1EG 8.12018-08-10
Dell EMC Data Protection Advisor, versions 6.2, 6,3, 6.4, 6.5 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 contain a XML External Entity (XXE) Injection vulnerability in the REST API. An authenticated remote m…
- CVE-2018-11586CRITICALCVSS 9.8EG 9.82018-06-05
XML external entity (XXE) vulnerability in api/rest/status in SearchBlox 8.6.7 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
- CVE-2018-11640CRITICALCVSS 9.1EG 9.12018-07-03
XML External Entity (XXE) vulnerability in the web service in Dialogic PowerMedia XMS before 3.5 SU2 allows remote attackers to read arbitrary files or cause a denial of service (resource consumption).
- CVE-2018-11719MEDIUMCVSS 4.9EG 4.92018-08-30
Xovis PC2, PC2R, and PC3 devices through 3.6.0 allow XXE.
- CVE-2018-11758HIGHCVSS 8.1EG 8.12018-08-22
This affects Apache Cayenne 4.1.M1, 3.2.M1, 4.0.M2 to 4.0.M5, 4.0.B1, 4.0.B2, 4.0.RC1, 3.1, 3.1.1, 3.1.2. CayenneModeler is a desktop GUI tool shipped with Apache Cayenne and intended for editing Cayenne ORM models stored as XML files. If …
- CVE-2018-11761HIGHCVSS 7.5EG 7.52018-09-19
In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.
- CVE-2018-11788CRITICALCVSS 9.8EG 9.82019-01-07
Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn'…
- CVE-2018-11796HIGHCVSS 7.5EG 7.52018-10-09
In Apache Tika 1.19 (CVE-2018-11761), we added an entity expansion limit for XML parsing. However, Tika reuses SAXParsers and calls reset() after each parse, which, for Xerces2 parsers, as per the documentation, removes the user-specified …
- CVE-2018-1183CRITICALCVSS 9.8EG 9.82018-04-30
In Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.8, Dell EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.8, Dell EMC VASA Provider Virtual Appliance versions prior to 8.4.0.512, Dell EMC SMIS version…
- CVE-2018-12243HIGHCVSS 8.8EG 8.82018-09-19
The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which is a type of issue where XML input containing a reference to an external entity is processed by a weakly configured XML…
- CVE-2018-12408HIGHCVSS 7.5EG 7.52018-08-08
The BusinessWorks engine component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks, TIBCO ActiveMatrix BusinessWorks for z/Linux, and TIBCO ActiveMatrix BusinessWorks Distribution for TIBCO Silver Fabric contains a vulnerability …
- CVE-2018-12463CRITICALCVSS 9.8EG 9.82018-07-12
An XML external entity (XXE) vulnerability in Fortify Software Security Center (SSC), version 17.1, 17.2, 18.1 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted …
- CVE-2018-1247HIGHCVSS 7.1EG 7.12018-05-08
RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability. This could potentially allow admin users to cause a denial of service or extract server data via injecting a maliciou…
- CVE-2018-12471HIGHCVSS 6.5EG 8.12018-10-04
A External Entity Reference ('XXE') vulnerability in SUSE Linux SMT allows remote attackers to read data from the server or cause DoS by referencing blocking elements. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.
- CVE-2018-12544CRITICALCVSS 9.8EG 9.82018-10-10
In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense against XML attacks. This mechanism is exclusively when the developer uses the Eclipse Vert.x OpenA…
- CVE-2018-12585HIGHCVSS 8.2EG 8.22018-09-14
An XXE vulnerability in the OPC UA Java and .NET Legacy Stack can allow remote attackers to trigger a denial of service.
- CVE-2018-1259HIGHCVSS 7.5EG 7.52018-05-11
Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity referen…
- CVE-2018-1285CRITICALCVSS 9.8EG 9.82020-05-11
Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.
- CVE-2018-1307HIGHCVSS 8.1EG 8.12018-02-09
In Apache jUDDI 3.2 through 3.3.4, if using the WADL2Java or WSDL2Java classes, which parse a local or remote XML document and then mediates the data structures into UDDI data structures, there are little protections present against entity…
- CVE-2018-1308HIGHCVSS 7.5EG 7.52018-04-09
This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` parameter of Solr's DataImportHandler. It can be used as XXE using file/ftp/http protocols…
- CVE-2018-1309CRITICALCVSS 9.8EG 9.82018-05-23
Apache NiFi External XML Entity issue in SplitXML processor. Malicious XML content could cause information disclosure or remote code execution. The fix to disable external general entity parsing and disallow doctype declarations was applie…
- CVE-2018-13415CRITICALCVSS 9.8EG 9.82018-08-13
In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1) Access arbitrary fil…
- CVE-2018-13416CRITICALCVSS 9.8EG 9.82018-08-03
In Universal Media Server (UMS) 7.1.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1) Access arbitrar…
- CVE-2018-13417CRITICALCVSS 9.8EG 9.82018-08-13
In Vuze Bittorrent Client 5.7.6.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1) Access arbitrary fi…
- CVE-2018-13439HIGHCVSS 7.5EG 7.52018-07-08
WXPayUtil in WeChat Pay Java SDK allows XXE attacks involving a merchant notification URL.
- CVE-2018-1364HIGHCVSS 8.2EG 8.22018-01-29
IBM Content Navigator 2.0 and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X…
- CVE-2018-13823HIGHCVSS 7.5EG 7.52018-08-30
An XML external entity vulnerability in the XOG functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to access sensitive information.
- CVE-2018-13826CRITICALCVSS 9.1EG 9.12018-08-30
An XML external entity vulnerability in the XOG functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to conduct server side request forgery attacks.
- CVE-2018-14065CRITICALCVSS 9.8EG 9.82018-07-15
XMLReader.php in PHPOffice Common before 0.2.9 allows XXE.
- CVE-2018-1421HIGHCVSS 7.1EG 7.12018-04-04
IBM WebSphere DataPower Appliances 7.1, 7.2, 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive informat…
- CVE-2018-1424HIGHCVSS 7.1EG 7.12018-12-07
IBM Marketing Platform 9.1.0, 9.1.2, and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory reso…
- CVE-2018-14383HIGHCVSS 7.5EG 7.52019-08-07
The Transition Technologies "The Scheduler" app 5.1.3 for Jira allows XXE due to a weakly configured/parameterized XML parser. It was fixed in the versions 5.2.1 and 3.3.7
- CVE-2018-14473CRITICALCVSS 9.1EG 9.12018-08-04
OCS Inventory 2.4.1 lacks a proper XML parsing configuration, allowing the use of external entities. This issue can be exploited by an attacker sending a crafted HTTP request in order to exfiltrate information or cause a Denial of Service.
- CVE-2018-14485CRITICALCVSS 9.8EG 9.82019-05-07
BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd.
- CVE-2018-1456HIGHCVSS 7.1EG 7.12018-06-06
IBM Rhapsody DM 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume m…
- CVE-2018-14720CRITICALCVSS 9.8EG 9.82019-01-02
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
- CVE-2018-15362CRITICALCVSS 9.1EG 9.12018-12-07
XXE in GE Proficy Cimplicity GDS versions 9.0 R2, 9.5, 10.0
- CVE-2018-1542HIGHCVSS 7.1EG 7.12018-07-06
IBM FileNet Content Manager, IBM Content Foundation, and IBM Case Foundation Administration Console for Content Platform Engine (ACCE) 5.2.1 and 5.5.0 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data.…
- CVE-2018-15444HIGHCVSS 6.3EG 7.32018-11-08
A vulnerability in the web-based user interface of Cisco Energy Management Suite Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is…
- CVE-2018-15506CRITICALCVSS 9.8EG 9.82019-06-19
In BubbleUPnP 0.9 update 30, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1) Access arbitrary files fr…
- CVE-2018-15531CRITICALCVSS 9.8EG 9.82018-09-26
JavaMelody before 1.74.0 has XXE via parseSoapMethodName in bull/javamelody/PayloadNameRequestWrapper.java.
- CVE-2018-15805CRITICALCVSS 9.1EG 9.12018-12-10
Accusoft PrizmDoc HTML5 Document Viewer before 13.5 contains an XML external entity (XXE) vulnerability, allowing an attacker to read arbitrary files or cause a denial of service (resource consumption).
- CVE-2018-1588HIGHCVSS 7.1EG 7.12018-09-25
IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6) is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerabil…
- CVE-2018-1607HIGHCVSS 7.1EG 7.12018-09-25
IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitiv…
Map vulnerabilities like CWE-611 to your infrastructure
EchelonGraph correlates every CVE — across CWE-611 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →