← Back
CWE-611

1,268 CVEs • Abstraction: Base

Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

JSON object

Loading...

CVEs (1,268)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Mahara
2Debian Linux
Mahara
Apr 29, 2026
Nov 24, 2012
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Mahara 1.4.x before 1.4.4 and 1.5.x before 1.5.3 allows remote attackers to read arbitrary files or create TCP connections via an XML external entity (XXE) injection attack, as demonstrated by reading config.php.
1Cakefoundation
1Cakephp
Apr 29, 2026
Oct 9, 2012
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.
6Apple
CanonicalDebian+3 more
9Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+6 more
Apr 29, 2026
Oct 3, 2012
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the exi...Show more
The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or URLs, and possibly obtain file or URL content that triggers a parsing error, via an XML value that refers to (1) a DTD or (2) an entity, related to an XML External Entity (aka XXE) issue.Show less
6Apache
DebianFedoraproject+3 more
13Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+10 more
Apr 29, 2026
Jun 17, 2012
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via...Show more
Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.Show less
3Debian
FedoraprojectPhpmyadmin
3Debian Linux
FedoraPhpmyadmin
Apr 29, 2026
Nov 17, 2011
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data...Show more
The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.Show less
1Splunk
1Splunk
Apr 29, 2026
Sep 14, 2010
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
The XML parser in Splunk 4.0.0 through 4.1.4 allows remote authenticated users to obtain sensitive information and gain privileges via an XML External Entity (XXE) attack to unknown vectors.
3Apple
CanonicalOpensuse
4Iphone Os
OpensuseSafari+1 more
Apr 23, 2026
Jun 10, 2009
N/A· v4
7.5 HIGH· v3
7.1 HIGH· v2
The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote atta...Show more
The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote attackers to read arbitrary files via a crafted DTD, as demonstrated by a file:///etc/passwd URL in an entity declaration, related to an "XXE attack."Show less
1Adobe
2Acrobat
Acrobat Reader
Apr 16, 2026
Jun 15, 2005
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the "XML External Entity vulnerability."