CWE-611
1,303 CVEs • Abstraction: Base
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CVEs (1,303)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Jenkins Storable Configs Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validation. Attackers can exploit this vulnerability to manipulate XML content a...Show more |
1Wso2 3Api Manager Identity ServerIdentity Server As Key ManagerJun 17, 2026 May 11, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; and WSO2 IS as Key Manager 5.7.0, 5.9.0, an...Show more |
1Tibco 2Managed File Transfer Command Center Managed File Transfer Internet ServerJun 17, 2026 May 10, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The DOM XML parser and SAX XML parser components of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center, TIBCO Managed File Transfer Command Center, TIBCO Managed File Transfer Internet Server, and TIBCO Man...Show more |
1Twelvemonkeys Project 1Twelvemonkeys Jun 17, 2026 May 6, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The package com.twelvemonkeys.imageio:imageio-metadata before 3.7.1 are vulnerable to XML External Entity (XXE) Injection due to an insecurely initialized XML parser for reading XMP Metadata. An attacker can exploit this...Show more |
A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow...Show more |
1Talend 1Administration Center Jun 17, 2026 May 4, 2022 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 Talend Administration Center has a vulnerability that allows an authenticated user to use XML External Entity (XXE) processing to achieve read access as root on the remote filesystem. The issue is fixed for versions 8.0....Show more |
1Cisco 1Enterprise Nfv Infrastructure Software Jun 17, 2026 May 4, 2022 N/A· v4 7.4 HIGH· v3 4.3 MEDIUM· v2 Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level,...Show more |
In four instances DMARS (All versions prior to v2.1.10.24) does not properly restrict references of XML external entities while processing specific project files, which may allow unauthorized information disclosure. |
A Improper Restriction of XML External Entity Reference vulnerability in SUSE Open Build Service allows remote attackers to reference external entities in certain operations. This can be used to gain information from the...Show more |
Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration. The Standard Content Viewer service attempts to resolve XML External Entity references when...Show more |
1Rt Solar 1Solar Appscreener Jun 17, 2026 Apr 28, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Solar appScreener through 3.10.4, when a valid license is not present, allows XXE and SSRF attacks via a crafted XML document. |
org.xwiki.commons:xwiki-commons-xml is a common module used by other XWiki top level projects. Starting in version 2.7 and prior to versions 12.10.10, 13.4.4, and 13.8-rc-1, it is possible for a script to access any file...Show more |
Improper Restriction of XML External Entity Reference in GitHub repository detekt/detekt prior to 1.20.0. |
The affected product is vulnerable to a network-based attack by threat actors supplying a crafted, malicious XML payload designed to trigger an external entity reference call. |
1Schneider Electric 1Scadapack Workbench Jun 17, 2026 Apr 13, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could result in information disclosure when opening a malicious solution file provided by an attacker with SCADAPack Workbench. T...Show more |
1Zohocorp 1Manageengine Adaudit Plus Jun 17, 2026 Apr 5, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution. |
1Rockwellautomation 3Connected Components Workbench IsagrafSafety Instrumented Systems WorkstationJun 17, 2026 Apr 1, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe call within a dynamic link library file. An attacker could exploit this t...Show more |
An XML External Entity (XXE) vulnerability exists in wuta jox 1.16 in the readObject method in JOXSAXBeanInput. |
The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA allows XXE attacks via a malicious XML configuration file. |