← Back
CWE-611

1,268 CVEs • Abstraction: Base

Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

JSON object

Loading...

CVEs (1,268)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Secure Access Control System
May 13, 2026
Feb 22, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An XML External Entity vulnerability in the web-based user interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to have read access to part of the information stored i...Show more
An XML External Entity vulnerability in the web-based user interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to have read access to part of the information stored in the affected system. More Information: CSCvc04845. Known Affected Releases: 5.8(2.5).Show less
1Eparaksts
1Eparakstitajs 3
May 13, 2026
Feb 17, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
XML external entity (XXE) vulnerability in eParakstitajs 3 before 1.3.9 and eParaksts Java lib before 2.5.13 allows remote attackers to read arbitrary files or possibly have unspecified other impact via a crafted edoc fi...Show more
XML external entity (XXE) vulnerability in eParakstitajs 3 before 1.3.9 and eParaksts Java lib before 2.5.13 allows remote attackers to read arbitrary files or possibly have unspecified other impact via a crafted edoc file.Show less
1Wso2
1Identity Server
May 13, 2026
Feb 17, 2017
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 before WSO2-CARBON-PATCH-4.4.0-0231 allows remote authenticated users with access to XACML features to read arbitrary files,...Show more
XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 before WSO2-CARBON-PATCH-4.4.0-0231 allows remote authenticated users with access to XACML features to read arbitrary files, cause a denial of service, conduct server-side request forgery (SSRF) attacks, or have unspecified other impact via a crafted XACML request to entitlement/eval-policy-submit.jsp. NOTE: this issue can be combined with CVE-2016-4311 to exploit the vulnerability without credentials.Show less
1Python
1Openpyxl
May 13, 2026
Feb 15, 2017
N/A· v4
8.2 HIGH· v3
5.8 MEDIUM· v2
Openpyxl 2.4.1 resolves external entities by default, which allows remote attackers to conduct XXE attacks via a crafted .xlsx document.
1Ibm
2Integration Bus
Websphere Message Broker
May 13, 2026
Feb 15, 2017
N/A· v4
9.1 CRITICAL· v3
8.5 HIGH· v2
IBM Integration Bus 9.0 and 10.0 and WebSphere Message Broker SOAP FLOWS is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could expl...Show more
IBM Integration Bus 9.0 and 10.0 and WebSphere Message Broker SOAP FLOWS is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 1997918.Show less
1Emerson
1Liebert Sitescan Web
May 13, 2026
Feb 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An XML External Entity (XXE) issue was discovered in Emerson Liebert SiteScan Web Version 6.5, and prior. An attacker may enter malicious input to Liebert SiteScan through a weakly configured XML parser causing the appli...Show more
An XML External Entity (XXE) issue was discovered in Emerson Liebert SiteScan Web Version 6.5, and prior. An attacker may enter malicious input to Liebert SiteScan through a weakly configured XML parser causing the application to execute arbitrary code or disclose file contents from a server or connected network.Show less
1Ibm
2Bigfix Inventory
License Metric Tool
May 13, 2026
Feb 1, 2017
N/A· v4
8.1 HIGH· v3
7.5 HIGH· v2
IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive...Show more
IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources.Show less
1Ibm
3Infosphere Datastage
Infosphere Information ServerInfosphere Information Server On Cloud
May 13, 2026
Feb 1, 2017
N/A· v4
8.1 HIGH· v3
7.5 HIGH· v2
IBM InfoSphere Information Server is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly...Show more
IBM InfoSphere Information Server is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources.Show less
1Ibm
3Security Access Manager 9.0 Firmware
Security Access Manager For Mobile 8.0 FirmwareSecurity Access Manager For Web 8.0 Firmware
May 13, 2026
Feb 1, 2017
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
IBM Security Access Manager for Web is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose high...Show more
IBM Security Access Manager for Web is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources.Show less
1Ibm
3Security Access Manager 9.0 Firmware
Security Access Manager For Mobile 8.0 FirmwareSecurity Access Manager For Web 8.0 Firmware
May 13, 2026
Feb 1, 2017
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
IBM Single Sign On for Bluemix could allow a remote attacker to obtain sensitive information, caused by a XML external entity (XXE) error when processing XML data by the XML parser. A remote attacker could exploit this v...Show more
IBM Single Sign On for Bluemix could allow a remote attacker to obtain sensitive information, caused by a XML external entity (XXE) error when processing XML data by the XML parser. A remote attacker could exploit this vulnerability to read arbitrary files on the system or cause a denial of service.Show less
1Paessler
1Prtg Network Monitor
May 13, 2026
Jan 23, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
XML external entity vulnerability in PRTG Network Monitor before 16.2.23.3077/3078 allows remote authenticated users to read arbitrary files by creating a new HTTP XML/REST Value sensor that accesses a crafted XML file.
1Forgerock
1Openam
May 6, 2026
Jan 2, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
XML External Entity (XXE) Vulnerability in /SSOPOST/metaAlias/%realm%/idpv2 in OpenAM - Access Management 10.1.0 allows remote attackers to read arbitrary files via the SAMLRequest parameter.
1Vmware
1Vrealize Automation
May 6, 2026
Dec 29, 2016
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automation 6.x before 6.2.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML docum...Show more
The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automation 6.x before 6.2.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.Show less
1Vmware
1Vcenter Server
May 6, 2026
Dec 29, 2016
N/A· v4
7.7 HIGH· v3
4.0 MEDIUM· v2
VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authenticated users to read arbitrary files via a (1) Log Browser, (2) Distributed Switch setup, or (3) Content Library XML document containing an ext...Show more
VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authenticated users to read arbitrary files via a (1) Log Browser, (2) Distributed Switch setup, or (3) Content Library XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.Show less
1Vmware
1Vsphere Client
May 6, 2026
Dec 29, 2016
N/A· v4
5.8 MEDIUM· v3
5.0 MEDIUM· v2
VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity...Show more
VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.Show less
1Image Info Project
1Image Info For Perl
May 6, 2026
Dec 22, 2016
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processed by an application using perl-Image-Info, could cause denial of servic...Show more
perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processed by an application using perl-Image-Info, could cause denial of service or, potentially, information disclosure.Show less
1Xmltwig
1Xml Twig For Perl
May 6, 2026
Dec 22, 2016
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entities are always expanded, regardless of the option's setting.
1Python Openxml Project
1Python Docx
May 6, 2026
Dec 21, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
python-docx before 0.8.6 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted document.
1Open Xchange
1Open Xchange Appsuite
May 6, 2026
Dec 15, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev8. References to external Open XML document type definitions (.dtd resources) can be placed within .docx and .xslx files. Those resources were requeste...Show more
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev8. References to external Open XML document type definitions (.dtd resources) can be placed within .docx and .xslx files. Those resources were requested when parsing certain parts of the generated document. As a result an attacker can track access to a manipulated document. Usage of a document may get tracked and information about internal infrastructure may get exposed.Show less
1Ibm
1Filenet Workplace
May 6, 2026
Dec 1, 2016
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
IBM FileNet Workplace 4.0.2 before 4.0.2.14 LA012 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration...Show more
IBM FileNet Workplace 4.0.2 before 4.0.2.14 LA012 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.Show less