← Back
CWE-611

1,268 CVEs • Abstraction: Base

Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

JSON object

Loading...

CVEs (1,268)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Security Key Lifecycle Manager
Nov 21, 2024
Jan 9, 2018
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive informatio...Show more
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 133540.Show less
1Xmlbundle Project
1Xmlbundle
Nov 21, 2024
Jan 3, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
XMLBundle version 0.1.7 is vulnerable to XXE attacks which can result in denial of service attacks.
1Androidsvg Project
1Androidsvg
Nov 21, 2024
Jan 3, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and possibly remote code execution
1Pepperminty Wiki Project
1Pepperminty Wiki
Nov 21, 2024
Jan 3, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Pepperminty-Wiki version 0.15 is vulnerable to XXE attacks in the getsvgsize function resulting in denial of service and possibly remote code execution
1Commsy
1Commsy
Nov 21, 2024
Jan 3, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Commsy version 9.0.0 is vulnerable to XXE attacks in the configuration import functionality resulting in denial of service and possibly remote execution of code.
2Lightbend
Playframework
2Play Framework
Play Framework
May 13, 2026
Dec 29, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow remote attackers to read arbitrary files, cause a denial of service, or have unspec...Show more
XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow remote attackers to read arbitrary files, cause a denial of service, or have unspecified other impact via crafted XML data.Show less
1Changehealthcare
1Conserus Image Repository
May 13, 2026
Dec 15, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A security researcher found an XML External Entity (XXE) vulnerability on the Conserus Image Repository archive solution version 2.1.1.105 by McKesson Medical Imaging Company, which is now a Change Healthcare company. An...Show more
A security researcher found an XML External Entity (XXE) vulnerability on the Conserus Image Repository archive solution version 2.1.1.105 by McKesson Medical Imaging Company, which is now a Change Healthcare company. An unauthenticated user supplying a modified HTTP SOAP request to the vulnerable service allows for arbitrary file read access to the local file system as well as the transmittal of the application service's account hashed credentials to a remote attacker.Show less
1Adobe
1Coldfusion
May 13, 2026
Dec 1, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Adobe ColdFusion has an XML external entity (XXE) injection vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.
1Restlet
1Restlet
May 13, 2026
Nov 30, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Restlet Framework before 2.3.12 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE attack, because only general external entities (not parameter external entities)...Show more
Restlet Framework before 2.3.12 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE attack, because only general external entities (not parameter external entities) are properly considered. This is related to XmlRepresentation, DOMRepresentation, SaxRepresentation, and JacksonRepresentation.Show less
1Restlet
1Restlet
May 13, 2026
Nov 30, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Restlet Framework before 2.3.11, when using SimpleXMLProvider, allows remote attackers to access arbitrary files via an XXE attack in a REST API HTTP request. This affects use of the Jax-rs extension.
2Apache
Simplexml Project
2Simplexml
Solr
Sep 12, 2025
Nov 17, 2017
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on.
1Tablepress
1Tablepress
May 13, 2026
Nov 17, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
TablePress prior to version 1.8.1 allows an attacker to conduct XML External Entity (XXE) attacks via unspecified vectors.
1Ibm
1Security Access Manager 9.0 Firmware
May 13, 2026
Nov 13, 2017
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
IBM Security Access Manager Appliance 9.0.3 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or co...Show more
IBM Security Access Manager Appliance 9.0.3 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 128612.Show less
1Itextpdf
1Itext
May 13, 2026
Nov 8, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct XML external entity (XXE) attacks via a crafted PDF.
1Apache
1Activemq
May 13, 2026
Oct 27, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
1Apache
1Activemq Apollo
May 13, 2026
Oct 27, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
1Apache
1Xml Rpc
May 13, 2026
Oct 27, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
XML external entity (XXE) vulnerability in the Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted DTD.
1Getmura
1Mura Cms
May 13, 2026
Oct 19, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
tasks/feed/readRSS.cfm in Mura CMS before 6.2 allows attackers to bypass intended access restrictions by leveraging the "draggable feeds" feature.
1Mediawiki
1Mediawiki
May 13, 2026
Oct 17, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The getid3 library in MediaWiki before 1.24.1, 1.23.8, 1.22.15 and 1.19.23 allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack...Show more
The getid3 library in MediaWiki before 1.24.1, 1.23.8, 1.22.15 and 1.19.23 allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack. NOTE: Related to CVE-2014-2053.Show less
4Apache
CanonicalDebian+1 more
4Debian Linux
Jboss Enterprise Application PlatformSolr+1 more
May 13, 2026
Oct 14, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch,...Show more
Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch, although it uses Lucene, is NOT vulnerable to this. Note that the XML external entity expansion vulnerability occurs in the XML Query Parser which is available, by default, for any query request with parameters deftype=xmlparser and can be exploited to upload malicious data to the /upload request handler or as Blind XXE using ftp wrapper in order to read arbitrary local files from the Solr server. Note also that the second vulnerability relates to remote code execution using the RunExecutableListener available on all affected versions of Solr.Show less