CWE-611
1,244 CVEs • Abstraction: Base
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CVEs (1,244)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors. |
1Opentext 1Document Sciences Xpression May 13, 2026 Oct 3, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to an XML External Entity vulnerability: /xFramework/services/QuickDoc....Show more |
When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources. The...Show more |
Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML file...Show more |
1Opentext 2Documentum Administrator Documentum WebtopMay 13, 2026 Sep 28, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Multiple XML external entity (XXE) vulnerabilities in the OpenText Documentum Webtop 6.8.0160.0073 allow remote authenticated users to list the contents of arbitrary directories, read arbitrary files, cause a denial of s...Show more |
1Opentext 2Documentum Administrator Documentum WebtopMay 13, 2026 Sep 28, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Multiple XML external entity (XXE) vulnerabilities in the OpenText Documentum Administrator 7.2.0180.0055 allow remote authenticated users to list the contents of arbitrary directories, read arbitrary files, cause a deni...Show more |
During Jelly (xml) file parsing with Apache Xerces, if a custom doctype entity is declared with a "SYSTEM" entity with a URL and that entity is used in the body of the Jelly file, during parser instantiation the parser w...Show more |
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or...Show more |
1Microsoft 2Windows 7 Windows Server 2008May 13, 2026 Sep 13, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The Microsoft Common Console Document (.msc) in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1 allows an attacker to read arbitrary files via an XML external entity (XXE) declaration, due to the way that the...Show more |
XXE in Dive Assistant - Template Builder in Blackwave Dive Assistant - Desktop Edition 8.0 allows attackers to remotely view local files via a crafted template.xml file. |
1Vmware 1Single Sign On For Pivotal Cloud Foundry May 13, 2026 Sep 9, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, an XXE (XML External Entity) attack was discovered in the Single Sign-On service dashboard. Privileged us...Show more |
XXE in Diving Log 6.0 allows attackers to remotely view local files through a crafted dive.xml file that is mishandled during a Subsurface import. |
A vulnerability in the web-based user interface of Cisco SocialMiner could allow an unauthenticated, remote attacker to have read and write access to information stored in the affected system. The vulnerability is due to...Show more |
XML external entity (XXE) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.x before 7.0.17, 7.1.x before 7.1.12, and 8.0.x before 8.0.3 allows rem...Show more |
XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01. |
XML external entity (XXE) vulnerability in bkr/server/jobs.py in Beaker before 20.1 allows remote authenticated users to obtain sensitive information via submitting job XML to the server containing entity references whic...Show more |
IBM QRadar Network Security 5.4 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory...Show more |
2Automatedlogic Carrier3Automatedlogic Webctrl I VuSitescan WebMay 13, 2026 Aug 31, 2017 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 An XXE issue was discovered in Automated Logic Corporation (ALC) Liebert SiteScan Web Version 6.5 and prior, ALC WebCTRL Version 6.5 and prior, and Carrier i-Vu Version 6.5 and prior. An attacker could enter malicious in...Show more |
2Ocpfoundation Siemens4Local Discovery Server Simatic Pcs7Ua .net+1 moreMay 13, 2026 Aug 30, 2017 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Server (LDS) before 1.03.367. Among the affected products are Siemens SIMATIC PCS7 (All versions V8.1 a...Show more |
Adobe Digital Editions 4.5.4 and earlier has a security bypass vulnerability. |