← Back
CWE-611

1,303 CVEs • Abstraction: Base

Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

JSON object

Loading...

CVEs (1,303)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nokia
1Netact
Jun 17, 2026
Apr 25, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to the Configuration Dashboard page. Input validation and a proper XML parser configuration are missing. For an external attacker, it is ve...Show more
An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to the Configuration Dashboard page. Input validation and a proper XML parser configuration are missing. For an external attacker, it is very difficult to exploit this, because a few dynamically created parameters such as Jsession-id, a CSRF token, and an Nxsrf token would be needed. The attack can realistically only be performed by an internal user.Show less
1Egostudiogroup
1Super Clean
Jun 17, 2026
Apr 20, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges cause a denial of service via the update_info field of the _default_.xml file.
1Guralp
1Man Eam 0003
Jun 17, 2026
Apr 16, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
cgi-bin/xmlstatus.cgi in Güralp MAN-EAM-0003 3.2.4 is vulnerable to an XML External Entity (XXE) issue via XML file upload, which leads to local file disclosure.
1Talend
1Data Catalog
Jun 17, 2026
Apr 13, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
All versions of Talend Data Catalog before 8.0-20220907 are potentially vulnerable to XML External Entity (XXE) attacks in the license parsing code.
1Talend
1Data Catalog
Jun 17, 2026
Apr 13, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
All versions of Talend Data Catalog before 8.0-20230110 are potentially vulnerable to XML External Entity (XXE) attacks in the /MIMBWebServices/license endpoint of the remote harvesting server.
1Siemens
1Polarion Alm
Jun 17, 2026
Apr 11, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability has been identified in Polarion ALM (All versions < V22R2). The application contains a XML External Entity Injection (XXE) vulnerability. This could allow an attacker to view files on the application serv...Show more
A vulnerability has been identified in Polarion ALM (All versions < V22R2). The application contains a XML External Entity Injection (XXE) vulnerability. This could allow an attacker to view files on the application server filesystem.Show less
1Mlit
1National Land Numerical Information Data Conversion Tool
Jun 17, 2026
Apr 11, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
National land numerical information data conversion tool all versions improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the PC may be accessed by an...Show more
National land numerical information data conversion tool all versions improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the PC may be accessed by an attacker.Show less
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Apr 11, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.
1Ibm
1Tririga Application Platform
Jun 17, 2026
Apr 7, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
IBM TRIRIGA 4.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IB...Show more
IBM TRIRIGA 4.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 249975.Show less
1Cisco
1Identity Services Engine
Jun 17, 2026
Apr 5, 2023
N/A· v4
6.0 MEDIUM· v3
N/A· v2
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information, conduct a server-side request forgery (SSRF) at...Show more
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information, conduct a server-side request forgery (SSRF) attack through an affected device, or negatively impact the responsiveness of the web-based management interface itself. This vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing certain XML files. An attacker could exploit this vulnerability by uploading a crafted XML file that contains references to external entities. A successful exploit could allow the attacker to retrieve files from the local system, resulting in the disclosure of confidential information. A successful exploit could also cause the web application to perform arbitrary HTTP requests on behalf of the attacker or consume memory resources to reduce the availability of the web-based management interface. To successfully exploit this vulnerability, an attacker would need valid Super Admin or Policy Admin credentials.Show less
1Hitachi
1Vantara Pentaho Business Analytics Server
Jun 17, 2026
Apr 3, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly protect the Post Analysis service endpoint of the data access plugin against out-of-band XML Extern...Show more
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly protect the Post Analysis service endpoint of the data access plugin against out-of-band XML External Entity Reference.  Show less
1Jenkins
1Remote Jobs View
Jun 17, 2026
Apr 2, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Jenkins remote-jobs-view-plugin Plugin 0.0.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
1Jenkins
1Phabricator Differential
Jun 17, 2026
Apr 2, 2023
N/A· v4
8.2 HIGH· v3
N/A· v2
Jenkins Phabricator Differential Plugin 2.1.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
1Jenkins
1Performance Publisher
Jun 17, 2026
Apr 2, 2023
N/A· v4
8.2 HIGH· v3
N/A· v2
Jenkins Performance Publisher Plugin 8.09 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
1Jenkins
1Visual Studio Code Metrics
Jun 17, 2026
Apr 2, 2023
N/A· v4
8.2 HIGH· v3
N/A· v2
Jenkins Visual Studio Code Metrics Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
1Jenkins
1Crap4j
Jun 17, 2026
Apr 2, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Jenkins Crap4J Plugin 0.9 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
1Zohocorp
3Manageengine Opmanager
Manageengine Opmanager MspManageengine Opmanager Plus
Jun 17, 2026
Mar 30, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payloa...Show more
A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability.Show less
1Aveva
1Aveva Edge
Jun 17, 2026
Mar 29, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
This vulnerability allows remote attackers to disclose sensitive information on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User interaction is required to exploit this vulnerability in th...Show more
This vulnerability allows remote attackers to disclose sensitive information on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the LoadImportedLibraries method. Due to the improper restriction of XML External Entity (XXE) references, a crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker can leverage this vulnerability to disclose information in the context of the current process. Was ZDI-CAN-17394.Show less
1Independentsoft
1Jodf
Jun 17, 2026
Mar 24, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in Independentsoft JODF before 1.1.110. The API is prone to XML external entity (XXE) injection via a remote DTD in a DOCX file.
1Independentsoft
1Jspreadsheet
Jun 17, 2026
Mar 24, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in Independentsoft JSpreadsheet before 1.1.110. The API is prone to XML external entity (XXE) injection via a remote DTD in a DOCX file.