← Back
CWE-611

1,303 CVEs • Abstraction: Base

Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

JSON object

Loading...

CVEs (1,303)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Talend
1Open Studio
Jun 17, 2026
Jan 9, 2023
N/A· v4
9.8 CRITICAL· v3
4.9 MEDIUM· v2
A vulnerability classified as problematic was found in Talend Open Studio for MDM. This vulnerability affects unknown code of the component XML Handler. The manipulation leads to xml external entity reference. The patch...Show more
A vulnerability classified as problematic was found in Talend Open Studio for MDM. This vulnerability affects unknown code of the component XML Handler. The manipulation leads to xml external entity reference. The patch is identified as 31d442b9fb1d518128fd18f6e4d54e06c3d67793. It is recommended to apply a patch to fix this issue. VDB-217666 is the identifier assigned to this vulnerability.Show less
1Simplexrd Project
1Simplexrd
Nov 21, 2024
Jan 7, 2023
N/A· v4
9.8 CRITICAL· v3
4.9 MEDIUM· v2
A vulnerability classified as problematic was found in kelvinmo simplexrd up to 3.1.0. This vulnerability affects unknown code of the file simplexrd/simplexrd.class.php. The manipulation leads to xml external entity refe...Show more
A vulnerability classified as problematic was found in kelvinmo simplexrd up to 3.1.0. This vulnerability affects unknown code of the file simplexrd/simplexrd.class.php. The manipulation leads to xml external entity reference. Upgrading to version 3.1.1 is able to address this issue. The patch is identified as 4c9f2e028523ed705b555eca2c18c64e71f1a35d. It is recommended to upgrade the affected component. VDB-217630 is the identifier assigned to this vulnerability.Show less
1E Contract
1Dssp
Nov 21, 2024
Jan 6, 2023
N/A· v4
9.8 CRITICAL· v3
4.9 MEDIUM· v2
A vulnerability classified as problematic was found in e-Contract dssp up to 1.3.1. Affected by this vulnerability is the function checkSignResponse of the file dssp-client/src/main/java/be/e_contract/dssp/client/SignRes...Show more
A vulnerability classified as problematic was found in e-Contract dssp up to 1.3.1. Affected by this vulnerability is the function checkSignResponse of the file dssp-client/src/main/java/be/e_contract/dssp/client/SignResponseVerifier.java. The manipulation leads to xml external entity reference. Upgrading to version 1.3.2 is able to address this issue. The identifier of the patch is ec4238349691ec66dd30b416ec6eaab02d722302. It is recommended to upgrade the affected component. The identifier VDB-217549 was assigned to this vulnerability.Show less
1Gturri
1Axmlrpc
Jun 17, 2026
Jan 5, 2023
N/A· v4
9.8 CRITICAL· v3
4.9 MEDIUM· v2
A vulnerability classified as problematic was found in gturri aXMLRPC up to 1.12.0. This vulnerability affects the function ResponseParser of the file src/main/java/de/timroes/axmlrpc/ResponseParser.java. The manipulatio...Show more
A vulnerability classified as problematic was found in gturri aXMLRPC up to 1.12.0. This vulnerability affects the function ResponseParser of the file src/main/java/de/timroes/axmlrpc/ResponseParser.java. The manipulation leads to xml external entity reference. Upgrading to version 1.14.0 is able to address this issue. The patch is identified as 456752ebc1ef4c0db980cb5b01a0b3cd0a9e0bae. It is recommended to upgrade the affected component. VDB-217450 is the identifier assigned to this vulnerability.Show less
1Bonitasoft
1Webservice Connector
Jun 17, 2026
Jan 5, 2023
N/A· v4
9.8 CRITICAL· v3
4.9 MEDIUM· v2
A vulnerability, which was classified as problematic, was found in bonitasoft bonita-connector-webservice up to 1.3.0. This affects the function TransformerConfigurationException of the file src/main/java/org/bonitasoft/...Show more
A vulnerability, which was classified as problematic, was found in bonitasoft bonita-connector-webservice up to 1.3.0. This affects the function TransformerConfigurationException of the file src/main/java/org/bonitasoft/connectors/ws/SecureWSConnector.java. The manipulation leads to xml external entity reference. Upgrading to version 1.3.1 is able to address this issue. The patch is named a12ad691c05af19e9061d7949b6b828ce48815d5. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217443.Show less
1Itextpdf
1Rups
Nov 21, 2024
Dec 30, 2022
N/A· v4
9.8 CRITICAL· v3
5.2 MEDIUM· v2
A vulnerability classified as problematic was found in iText RUPS. This vulnerability affects unknown code of the file src/main/java/com/itextpdf/rups/model/XfaFile.java. The manipulation leads to xml external entity ref...Show more
A vulnerability classified as problematic was found in iText RUPS. This vulnerability affects unknown code of the file src/main/java/com/itextpdf/rups/model/XfaFile.java. The manipulation leads to xml external entity reference. The patch is identified as ac5590925874ef810018a6b60fec216eee54fb32. It is recommended to apply a patch to fix this issue. VDB-217054 is the identifier assigned to this vulnerability.Show less
1Healthit
1Code Validator Api
Jun 17, 2026
Dec 29, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability classified as problematic was found in ONC code-validator-api up to 1.0.30. This vulnerability affects the function vocabularyValidationConfigurations of the file src/main/java/org/sitenv/vocabularies/con...Show more
A vulnerability classified as problematic was found in ONC code-validator-api up to 1.0.30. This vulnerability affects the function vocabularyValidationConfigurations of the file src/main/java/org/sitenv/vocabularies/configuration/CodeValidatorApiConfiguration.java of the component XML Handler. The manipulation leads to xml external entity reference. Upgrading to version 1.0.31 is able to address this issue. The name of the patch is fbd8ea121755a2d3d116b13f235bc8b61d8449af. It is recommended to upgrade the affected component. VDB-217018 is the identifier assigned to this vulnerability.Show less
1Talend
1Open Studio For Mdm
Jun 17, 2026
Dec 28, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A vulnerability was found in Talend Open Studio for MDM. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file org.talend.mdm.core/src/com/amalto/core/storage/SystemS...Show more
A vulnerability was found in Talend Open Studio for MDM. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file org.talend.mdm.core/src/com/amalto/core/storage/SystemStorageWrapper.java. The manipulation leads to xml external entity reference. Upgrading to version 20221220_1938 is able to address this issue. The name of the patch is 95590db2ad6a582c371273ceab1a73ad6ed47853. It is recommended to upgrade the affected component. The identifier VDB-216997 was assigned to this vulnerability.Show less
1Hypera
1Dragonfly
Jun 17, 2026
Dec 28, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Dragonfly is a Java runtime dependency management library. Dragonfly v0.3.0-SNAPSHOT does not configure DocumentBuilderFactory to prevent XML external entity (XXE) attacks. This issue is patched in 0.3.1-SNAPSHOT. As a w...Show more
Dragonfly is a Java runtime dependency management library. Dragonfly v0.3.0-SNAPSHOT does not configure DocumentBuilderFactory to prevent XML external entity (XXE) attacks. This issue is patched in 0.3.1-SNAPSHOT. As a workaround, since Dragonfly only parses XML `SNAPSHOT` versions are being resolved, this vulnerability may be avoided by not trying to resolve `SNAPSHOT` versions.Show less
1Tum
1Ogc Web Feature Service
Jun 17, 2026
Dec 18, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability was found in 3D City Database OGC Web Feature Service up to 5.2.0. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to xml external entity reference. Up...Show more
A vulnerability was found in 3D City Database OGC Web Feature Service up to 5.2.0. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to xml external entity reference. Upgrading to version 5.2.1 is able to address this issue. The name of the patch is 246f4e2a97ad81491c00a7ed72ce5e7c7f75050a. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216215.Show less
1Xml Rpc.net Project
1Xml Rpc.net
Jun 17, 2026
Dec 18, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
An XML external entity (XXE) injection vulnerability in XML-RPC.NET before 2.5.0 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, as demonstrated by a pingback.aspx POST request.
1Broadcom
1Symantec Identity Governance And Administration
Jun 17, 2026
Dec 16, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Identity Manager 14.4
1Arubanetworks
2Arubaos
Sd Wan
Jun 17, 2026
Dec 12, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A successful exploit could allow an authenticated attacker to retrieve files from the local system or...Show more
Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A successful exploit could allow an authenticated attacker to retrieve files from the local system or cause the application to consume system resources, resulting in a denial of service condition. Show less
1Jenkins
1Plot
Jun 17, 2026
Dec 12, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Jenkins Plot Plugin 2.1.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
1Jetbrains
1Intellij Idea
Jun 17, 2026
Dec 8, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was possible.
1Kwoksys
1Information Server
Jun 17, 2026
Dec 6, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
An XML external entity (XXE) injection vulnerability in Kwoksys Kwok Information Server before v2.9.5.SP31 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks.
1Zohocorp
4Manageengine Assetexplorer
Manageengine Servicedesk PlusManageengine Servicedesk Plus Msp+1 more
Jun 17, 2026
Nov 23, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to an XML External Entity attack that leads to Information Disclosure.
1Sophos
1Mobile
Jun 17, 2026
Nov 16, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises between versions 5.0.0 and 9.7.4.
1Cisco
1Secure Firewall Management Center
Jun 17, 2026
Nov 15, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A vulnerability in the module import function of the administrative interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to view sensitive information. This vulne...Show more
A vulnerability in the module import function of the administrative interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to view sensitive information. This vulnerability is due to insufficient validation of the XML syntax when importing a module. An attacker could exploit this vulnerability by supplying a specially crafted XML file to the function. A successful exploit could allow the attacker to read sensitive data that would normally not be revealed.Show less
1Jenkins
1Japex
Jun 17, 2026
Nov 15, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Jenkins JAPEX Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.