← Back
CWE-611

1,268 CVEs • Abstraction: Base

Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

JSON object

Loading...

CVEs (1,268)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Qradar Network Security
May 13, 2026
Sep 5, 2017
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
IBM QRadar Network Security 5.4 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory...Show more
IBM QRadar Network Security 5.4 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 128377.Show less
2Automatedlogic
Carrier
3Automatedlogic Webctrl
I VuSitescan Web
May 13, 2026
Aug 31, 2017
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
An XXE issue was discovered in Automated Logic Corporation (ALC) Liebert SiteScan Web Version 6.5 and prior, ALC WebCTRL Version 6.5 and prior, and Carrier i-Vu Version 6.5 and prior. An attacker could enter malicious in...Show more
An XXE issue was discovered in Automated Logic Corporation (ALC) Liebert SiteScan Web Version 6.5 and prior, ALC WebCTRL Version 6.5 and prior, and Carrier i-Vu Version 6.5 and prior. An attacker could enter malicious input to WebCTRL, i-Vu, or SiteScan Web through a weakly configured XML parser causing the application to execute arbitrary code or disclose file contents from a server or connected network.Show less
2Ocpfoundation
Siemens
4Local Discovery Server
Simatic Pcs7Ua .net+1 more
May 13, 2026
Aug 30, 2017
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Server (LDS) before 1.03.367. Among the affected products are Siemens SIMATIC PCS7 (All versions V8.1 a...Show more
An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Server (LDS) before 1.03.367. Among the affected products are Siemens SIMATIC PCS7 (All versions V8.1 and earlier), SIMATIC WinCC (All versions < V7.4 SP1), SIMATIC WinCC Runtime Professional (All versions < V14 SP1), SIMATIC NET PC Software, and SIMATIC IT Production Suite. By sending specially crafted packets to the OPC Discovery Server at port 4840/tcp, an attacker might cause the system to access various resources chosen by the attacker.Show less
1Adobe
1Digital Editions
May 13, 2026
Aug 11, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Adobe Digital Editions 4.5.4 and earlier has a security bypass vulnerability.
1Apache
1Cxf
May 13, 2026
Aug 10, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apache Abdera Parser which expands XML entities by default which represents...Show more
The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apache Abdera Parser which expands XML entities by default which represents a major XXE risk.Show less
1Ibm
1Sterling B2b Integrator
May 13, 2026
Aug 10, 2017
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
IBM Sterling B2B Integrator 5.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consum...Show more
IBM Sterling B2B Integrator 5.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 123663.Show less
1Apache
1Wink
May 13, 2026
Aug 8, 2017
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
XML External Entity (XXE) vulnerability in Apache Wink 1.1.1 and earlier allows remote attackers to read arbitrary files or cause a denial of service via a crafted XML document.
1Trendmicro
1Control Manager
May 13, 2026
Aug 2, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
XML external entity (XXE) processing vulnerability in Trend Micro Control Manager 6.0, if exploited, could lead to information disclosure. Formerly ZDI-CAN-4706.
1Ibm
2Sterling B2b Integrator
Sterling File Gateway
May 13, 2026
Aug 2, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
XML External Entity (XXE) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and IBM Sterling File Gateway 2.1 and 2.2 allows remote attackers to read arbitrary files via a crafted XML data.
1Ibm
1Infosphere Information Server
May 13, 2026
Aug 2, 2017
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive informa...Show more
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 127155.Show less
3Debian
Libexpat ProjectPython
3Debian Linux
LibexpatPython
May 13, 2026
Jul 25, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD.
1Sap
1Netweaver Application Server Java
May 13, 2026
Jul 25, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
XML external entity (XXE) vulnerability in com.sap.km.cm.ice in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD...Show more
XML external entity (XXE) vulnerability in com.sap.km.cm.ice in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request, aka SAP Security Note 2387249.Show less
1Ibm
1Bigfix Platform
May 13, 2026
Jul 19, 2017
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
IBM Tivoli Endpoint Manager is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory res...Show more
IBM Tivoli Endpoint Manager is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 123859.Show less
1Apache
1Sling
May 13, 2026
Jul 19, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string, which allows for XXE attacks in all scripts which use this method to...Show more
In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string, which allows for XXE attacks in all scripts which use this method to validate user input, potentially allowing an attacker to read sensitive data on the filesystem, perform same-site-request-forgery (SSRF), port-scanning behind the firewall or DoS the application.Show less
1Apache
1Openmeetings
May 13, 2026
Jul 17, 2017
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0.
1Xmlsec Project
1Xmlsec
May 13, 2026
Jul 17, 2017
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting in possible information disclosure or denial of service
1Logicaldoc
1Logicaldoc
May 13, 2026
Jul 17, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
LogicalDoc Community Edition 7.5.3 and prior is vulnerable to XXE when indexing XML documents.
1Microsoft
7Windows 10
Windows 7Windows 8.1+4 more
May 13, 2026
Jul 11, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Windows System Information Console in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an...Show more
Windows System Information Console in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an information disclosure vulnerability improperly parses XML input containing a reference to an external entity, aka "Windows System Information Console Information Disclosure Vulnerability".Show less
1Microsoft
6Windows 10
Windows 7Windows 8.1+3 more
May 13, 2026
Jul 11, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Windows Performance Monitor in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an informa...Show more
Windows Performance Monitor in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an information disclosure vulnerability due to the way it parses XML input, aka "Windows Performance Monitor Information Disclosure Vulnerability".Show less
1Ibm
1Security Guardium
May 13, 2026
Jul 5, 2017
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
IBM Security Guardium 10.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memo...Show more
IBM Security Guardium 10.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 124634.Show less