← Back
CWE-611

1,303 CVEs • Abstraction: Base

Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

JSON object

Loading...

CVEs (1,303)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Storable Configs
Jun 17, 2026
May 17, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Jenkins Storable Configs Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
1Hcltech
1Unica
Jun 17, 2026
May 12, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validation. Attackers can exploit this vulnerability to manipulate XML content a...Show more
XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validation. Attackers can exploit this vulnerability to manipulate XML content and inject malicious external entity references.Show less
1Wso2
3Api Manager
Identity ServerIdentity Server As Key Manager
Jun 17, 2026
May 11, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; and WSO2 IS as Key Manager 5.7.0, 5.9.0, an...Show more
XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; and WSO2 IS as Key Manager 5.7.0, 5.9.0, and 5.10.0; and WSO2 Identity Server 5.7.0, 5.8.0, 5.9.0, 5.10.0, and 5.11.0. Allows attackers to gain read access to sensitive information or cause a denial of service via crafted GET requests.Show less
1Tibco
2Managed File Transfer Command Center
Managed File Transfer Internet Server
Jun 17, 2026
May 10, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The DOM XML parser and SAX XML parser components of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center, TIBCO Managed File Transfer Command Center, TIBCO Managed File Transfer Internet Server, and TIBCO Man...Show more
The DOM XML parser and SAX XML parser components of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center, TIBCO Managed File Transfer Command Center, TIBCO Managed File Transfer Internet Server, and TIBCO Managed File Transfer Internet Server contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to execute XML External Entity (XXE) attacks on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center: versions 8.3.1 and below, TIBCO Managed File Transfer Command Center: versions 8.4.0 and 8.4.1, TIBCO Managed File Transfer Internet Server: versions 8.3.1 and below, and TIBCO Managed File Transfer Internet Server: versions 8.4.0 and 8.4.1.Show less
1Twelvemonkeys Project
1Twelvemonkeys
Jun 17, 2026
May 6, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The package com.twelvemonkeys.imageio:imageio-metadata before 3.7.1 are vulnerable to XML External Entity (XXE) Injection due to an insecurely initialized XML parser for reading XMP Metadata. An attacker can exploit this...Show more
The package com.twelvemonkeys.imageio:imageio-metadata before 3.7.1 are vulnerable to XML External Entity (XXE) Injection due to an insecurely initialized XML parser for reading XMP Metadata. An attacker can exploit this vulnerability if they are able to supply a file (e.g. when an online profile picture is processed) with a malicious XMP segment. If the XMP metadata of the uploaded image is parsed, then the XXE vulnerability is triggered.Show less
1Apache
1Jena
Jun 17, 2026
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow...Show more
A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow external entities.Show less
1Talend
1Administration Center
Jun 17, 2026
May 4, 2022
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
Talend Administration Center has a vulnerability that allows an authenticated user to use XML External Entity (XXE) processing to achieve read access as root on the remote filesystem. The issue is fixed for versions 8.0....Show more
Talend Administration Center has a vulnerability that allows an authenticated user to use XML External Entity (XXE) processing to achieve read access as root on the remote filesystem. The issue is fixed for versions 8.0.x in TPS-5189, versions 7.3.x in TPS-5175, and versions 7.2.x in TPS-5201. Earlier versions of Talend Administration Center may also be impacted; users are encouraged to update to a supported version.Show less
1Cisco
1Enterprise Nfv Infrastructure Software
Jun 17, 2026
May 4, 2022
N/A· v4
7.4 HIGH· v3
4.3 MEDIUM· v2
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level,...Show more
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host to the VM. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Deltaww
1Dmars
Jun 17, 2026
May 3, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In four instances DMARS (All versions prior to v2.1.10.24) does not properly restrict references of XML external entities while processing specific project files, which may allow unauthorized information disclosure.
1Opensuse
1Open Build Service
Jun 17, 2026
May 3, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A Improper Restriction of XML External Entity Reference vulnerability in SUSE Open Build Service allows remote attackers to reference external entities in certain operations. This can be used to gain information from the...Show more
A Improper Restriction of XML External Entity Reference vulnerability in SUSE Open Build Service allows remote attackers to reference external entities in certain operations. This can be used to gain information from the server that can be abused to escalate to Admin privileges on OBS. This issue affects: SUSE Open Build Service Open Build Service versions prior to 2.10.13.Show less
1Apache
1Nifi
Jun 17, 2026
Apr 30, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration. The Standard Content Viewer service attempts to resolve XML External Entity references when...Show more
Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration. The Standard Content Viewer service attempts to resolve XML External Entity references when viewing formatted XML files. The following Processors attempt to resolve XML External Entity references when configured with default property values: - EvaluateXPath - EvaluateXQuery - ValidateXml Apache NiFi flow configurations that include these Processors are vulnerable to malicious XML documents that contain Document Type Declarations with XML External Entity references. The resolution disables Document Type Declarations in the default configuration for these Processors, and disallows XML External Entity resolution in standard services.Show less
1Rt Solar
1Solar Appscreener
Jun 17, 2026
Apr 28, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Solar appScreener through 3.10.4, when a valid license is not present, allows XXE and SSRF attacks via a crafted XML document.
1Xwiki
1Commons
Jun 17, 2026
Apr 28, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
org.xwiki.commons:xwiki-commons-xml is a common module used by other XWiki top level projects. Starting in version 2.7 and prior to versions 12.10.10, 13.4.4, and 13.8-rc-1, it is possible for a script to access any file...Show more
org.xwiki.commons:xwiki-commons-xml is a common module used by other XWiki top level projects. Starting in version 2.7 and prior to versions 12.10.10, 13.4.4, and 13.8-rc-1, it is possible for a script to access any file accessing to the user running XWiki application server with XML External Entity Injection through the XML script service. The problem has been patched in versions 12.10.10, 13.4.4, and 13.8-rc-1. There is no easy workaround for fixing this vulnerability other than upgrading and being careful when giving Script rights.Show less
1Detekt
1Detekt
Jun 17, 2026
Apr 21, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Improper Restriction of XML External Entity Reference in GitHub repository detekt/detekt prior to 1.20.0.
1Fanuc
1Roboguide
Jun 17, 2026
Apr 20, 2022
N/A· v4
5.3 MEDIUM· v3
2.6 LOW· v2
The affected product is vulnerable to a network-based attack by threat actors supplying a crafted, malicious XML payload designed to trigger an external entity reference call.
1Schneider Electric
1Scadapack Workbench
Jun 17, 2026
Apr 13, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could result in information disclosure when opening a malicious solution file provided by an attacker with SCADAPack Workbench. T...Show more
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could result in information disclosure when opening a malicious solution file provided by an attacker with SCADAPack Workbench. This could be exploited to pass data from local files to a remote system controlled by an attacker. Affected Product: SCADAPack Workbench (6.6.8a and prior)Show less
1Zohocorp
1Manageengine Adaudit Plus
Jun 17, 2026
Apr 5, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.
1Rockwellautomation
3Connected Components Workbench
IsagrafSafety Instrumented Systems Workstation
Jun 17, 2026
Apr 1, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe call within a dynamic link library file. An attacker could exploit this t...Show more
When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe call within a dynamic link library file. An attacker could exploit this to pass data from local files to a remote web server, leading to a loss of confidentiality.Show less
1Jox Project
1Jox
Jun 17, 2026
Mar 30, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An XML External Entity (XXE) vulnerability exists in wuta jox 1.16 in the readObject method in JOXSAXBeanInput.
1Softwareag
1Mashzone Nextgen
Jun 17, 2026
Mar 30, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA allows XXE attacks via a malicious XML configuration file.