CWE-611— Improper Restriction of XML External Entity Reference (XXE)
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.— MITRE CWE catalog
1,275 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-611page 9 of 26
- CVE-2019-10172HIGHCVSS 7.5EG 7.52019-11-18
A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.
- CVE-2019-10244HIGHCVSS 7.5EG 7.52019-04-09
In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and the emulator position service (not part of the device distribution) could potentially be target of XXE attack due to an …
- CVE-2019-10264HIGHCVSS 7.2EG 7.22019-07-26
An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. With a valid administrator account, the "Move / Import / Export Users" screen has an Import Users option. This option accepts a ZIP archive containing a users.xml file th…
- CVE-2019-10266HIGHCVSS 7.5EG 7.52019-07-26
An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When sending an out-of-bounds XML document to a URL, it is possible to read the file structure and even the content of files without authentication.
- CVE-2019-10309CRITICALCVSS 9.3EG 9.32019-04-30
Jenkins Self-Organizing Swarm Plug-in Modules Plugin clients that use UDP broadcasts to discover Jenkins masters do not prevent XML External Entity processing when processing the responses, allowing unauthorized attackers on the same netwo…
- CVE-2019-10327HIGHCVSS 8.1EG 8.12019-05-31
An XML external entities (XXE) vulnerability in Jenkins Pipeline Maven Integration Plugin 1.7.0 and earlier allowed attackers able to control a temporary directory's content on the agent running the Maven build to have Jenkins parse a mali…
- CVE-2019-10337HIGHCVSS 7.5EG 7.52019-06-11
An XML external entities (XXE) vulnerability in Jenkins Token Macro Plugin 2.7 and earlier allowed attackers able to control a the content of the input file for the "XML" macro to have Jenkins resolve external entities, resulting in the ex…
- CVE-2019-10466HIGHCVSS 8.1EG 8.12019-10-23
An XML external entities (XXE) vulnerability in Jenkins 360 FireLine Plugin allows attackers with Overall/Read access to have Jenkins resolve external entities, resulting in the extraction of secrets from the Jenkins agent, server-side req…
- CVE-2019-1057HIGHCVSS 7.5EG 8.82019-08-14
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input. An attacker who successfully exploited the vulnerability could run malicious code remotely to take control of the user’s…
- CVE-2019-1060HIGHCVSS 8.8EG 8.82019-10-10
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'.
- CVE-2019-10718HIGHCVSS 7.5EG 7.52019-06-21
BlogEngine.NET 3.3.7.0 and earlier allows XML External Entity Blind Injection, related to pingback.axd and BlogEngine.Core/Web/HttpHandlers/PingbackHandler.cs.
- CVE-2019-10782MEDIUMCVSS 5.3EG 5.32020-01-30
All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XML External Entity (XXE) Injection due to an incomplete fix for CVE-2019-9658.
- CVE-2019-10976MEDIUMCVSS 5.5EG 5.52019-07-26
Mitsubishi Electric FR Configurator2, Version 1.16S and prior. This vulnerability is triggered when input passed to the XML parser is not sanitized while parsing the XML project and/or template file (.frc2). Once a user opens the file, the…
- CVE-2019-11216MEDIUMCVSS 6.5EG 6.52019-12-04
BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XML file and perform XXE attacks to download local files from the server, or do DoS attacks with XML expansion attacks. X…
- CVE-2019-11392HIGHCVSS 7.5EG 7.52019-06-21
BlogEngine.NET 3.3.7 and earlier allows XXE via an apml file to syndication.axd.
- CVE-2019-11519MEDIUMCVSS 4.9EG 4.92019-04-25
Libraries/Nop.Services/Localization/LocalizationService.cs in nopCommerce through 4.10 allows XXE via the "Configurations -> Languages -> Edit Language -> Import Resources -> Upload XML file" screen.
- CVE-2019-11677CRITICALCVSS 9.8EG 9.82019-05-02
The Custom Report import function in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to XML External Entity (XXE) Injection.
- CVE-2019-1187HIGHCVSS 5.5EG 7.52019-08-14
A denial of service vulnerability exists when the XmlLite runtime (XmlLite.dll) improperly parses XML input. An attacker who successfully exploited this vulnerability could cause a denial of service against an XML application. A remote una…
- CVE-2019-12154CRITICALCVSS 9.1EG 9.12019-06-11
XXE in the XML parser library in RealObjects PDFreactor before 10.1.10722 allows attackers to supply malicious XML content in externally referenced resources, leading to disclosure of local file contents and/or denial of service conditions.
- CVE-2019-12331HIGHCVSS 8.8EG 8.82019-11-07
PHPOffice PhpSpreadsheet before 1.8.0 has an XXE issue. The XmlScanner decodes the sheet1.xml from an .xlsx to utf-8 if something else than UTF-8 is declared in the header. This was a security measurement to prevent CVE-2018-19277 but the …
- CVE-2019-12415MEDIUMCVSS 5.5EG 5.52019-10-23
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resource…
- CVE-2019-12711MEDIUMCVSS 6.5EG 6.52019-10-02
A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to access sensitive information or…
- CVE-2019-12924CRITICALCVSS 9.8EG 9.82019-07-08
MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthenticated user. It was possible for an attacker to use a vulnerability in the configuration of the XML pr…
- CVE-2019-13031HIGHCVSS 8.1EG 8.12019-06-28
LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notification server is not enabled and has a "deny all" rule.
- CVE-2019-13176HIGHCVSS 7.5EG 7.52019-08-08
An issue was discovered in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2. The Content.MainForm.wgx component is affected by XXE via a crafted XML document in POST data. There is potential to use this for SS…
- CVE-2019-13358HIGHCVSS 7.5EG 7.52019-07-05
lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system. The attacker must upload a file in the docx or odt format.
- CVE-2019-13608CRITICALCVSS 7.5EG 9.0⚠ KEV2019-08-29
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.
- CVE-2019-13625CRITICALCVSS 9.1EG 9.12019-07-17
NSA Ghidra before 9.0.1 allows XXE when a project is opened or restored, or a tool is imported, as demonstrated by a project.prp file.
- CVE-2019-13990CRITICALCVSS 9.8EG 9.82019-07-26
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
- CVE-2019-14258HIGHCVSS 7.5EG 7.52019-08-21
The XML-RPC subsystem in Zenoss 2.5.3 allows XXE attacks that lead to unauthenticated information disclosure via port 9988.
- CVE-2019-14276MEDIUMCVSS 6.5EG 6.52019-10-23
WUSTL XNAT 1.7.5.3 allows XXE attacks via a POST request body.
- CVE-2019-14277CRITICALCVSS 9.8EG 9.82019-07-26
Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is vulnerable to unauthenticated blind XML injection (and XXE) in the resetPassword functionality via the REST API. This vulnerability can lead to lo…
- CVE-2019-14678CRITICALCVSS 10.0EG 10.02019-11-14
SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential…
- CVE-2019-14693HIGHCVSS 8.5EG 8.52019-08-08
Zoho ManageEngine AssetExplorer 6.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing license XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory res…
- CVE-2019-15637HIGHCVSS 8.1EG 8.12019-08-26
Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This affects Tableau Server, Tableau Desktop, Tableau Reader, and Tableau Public Desktop.
- CVE-2019-15641MEDIUMCVSS 6.5EG 6.52019-08-26
xmlrpc.cgi in Webmin through 1.930 allows authenticated XXE attacks. By default, only root, admin, and sysadm can access xmlrpc.cgi.
- CVE-2019-15983MEDIUMCVSS 4.9EG 4.92020-01-06
A vulnerability in the SOAP API of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. To exploit this vulnerability, an attacker w…
- CVE-2019-16174HIGHCVSS 8.8EG 8.82019-09-09
An XML injection vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to import specially crafted XML files and execute code or compromise data integrity.
- CVE-2019-16188HIGHCVSS 7.1EG 7.12019-09-25
HCL AppScan Source before 9.03.13 is susceptible to XML External Entity (XXE) attacks in multiple locations. In particular, an attacker can send a specially crafted .ozasmt file to a targeted victim and ask the victim to open it. When the …
- CVE-2019-16549HIGHCVSS 8.1EG 8.12019-12-17
Jenkins Maven Release Plugin 0.16.1 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks, allowing man-in-the-middle attackers to have Jenkins parse crafted XML documents.
- CVE-2019-1698MEDIUMCVSS 4.9EG 4.92019-02-21
A vulnerability in the web-based user interface of Cisco Internet of Things Field Network Director (IoT-FND) Software could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. Th…
- CVE-2019-17020MEDIUMCVSS 6.5EG 6.52020-01-08
If an XML file is served with a Content Security Policy and the XML file includes an XSL stylesheet, the Content Security Policy will not be applied to the contents of the XSL stylesheet. If the XSL sheet e.g. includes JavaScript, it would…
- CVE-2019-17085MEDIUMCVSS 6.5EG 6.52019-11-18
XXE attack vulnerability on Micro Focus Operations Agent, affected version 12.0, 12.01, 12.02, 12.03, 12.04, 12.05, 12.06, 12.10, 12.11. The vulnerability could be exploited to do an XXE attack on Operations Agent.
- CVE-2019-17554MEDIUMCVSS 5.5EG 5.52019-12-04
The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Request with content type "application/xml", which trigger the deserialization of entities, ca…
- CVE-2019-17637HIGHCVSS 7.1EG 7.12020-07-15
In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when ex…
- CVE-2019-18213HIGHCVSS 8.8EG 8.82019-10-23
XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows XXE via a crafted XML document, with resultant SSRF (as well as SMB connecti…
- CVE-2019-18227HIGHCVSS 7.5EG 7.52019-10-31
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. XXE vulnerabilities exist that may allow disclosure of sensitive data.
- CVE-2019-18412HIGHCVSS 7.5EG 7.52020-01-15
JetBrains IDETalk plugin before version 193.4099.10 allows XXE
- CVE-2019-18943MEDIUMCVSS 6.1EG 6.12021-02-26
Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to XML External Entity Processing (XXE) on certain operations.
- CVE-2019-1903CRITICALCVSS 6.5EG 9.12019-06-20
A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information or cause a denial of service (DoS) condition. The vulnerability is due to improper restrictions on XML entities. An a…
Map vulnerabilities like CWE-611 to your infrastructure
EchelonGraph correlates every CVE — across CWE-611 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →