CWE-611
1,303 CVEs • Abstraction: Base
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CVEs (1,303)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper restriction of XML external entity reference in DSP Builder Pro for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an unauthenticated user to potentially enable information disclosure via ne...Show more |
Signiant Manager+Agents before 15.1 allows XML External Entity (XXE) attacks. |
1F5 3Big Ip Advanced Web Application Firewall Big Ip Application Security ManagerBig Ip Fraud Protection ServiceJun 17, 2026 Jan 25, 2022 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 On BIG-IP FPS, ASM, and Advanced WAF versions 16.1.x before 16.1.1, 15.1.x before 15.1.4, and 14.1.x before 14.1.4.4, an XML External Entity (XXE) vulnerability exists in an undisclosed page of the F5 Advanced Web Applic...Show more |
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information...Show more |
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information...Show more |
Improper Restriction of XML External Entity Reference in GitHub repository skylot/jadx prior to 1.3.2. |
3Debian NetappOracle197 Mode Transition Tool Active Iq Unified ManagerCloud Insights Acquisition Unit+16 moreJun 17, 2026 Jan 19, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM E...Show more |
corenlp is vulnerable to Improper Restriction of XML External Entity Reference |
1Adobe 2Experience Manager Experience Manager Cloud ServiceJun 17, 2026 Jan 13, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) injection vulnerability that could be abused by an attacker to achieve RCE. |
corenlp is vulnerable to Improper Restriction of XML External Entity Reference |
An issue was discovered in CALDERA 2.9.0. The Debrief plugin receives base64 encoded "SVG" parameters when generating a PDF document. These SVG documents are parsed in an unsafe manner and can be leveraged for XXE attack...Show more |
1Quest 1Kace Desktop Authority Jun 17, 2026 Dec 22, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 XXE can occur in Quest KACE Desktop Authority before 11.2 because the log4net configuration file might be controlled by an attacker, a related issue to CVE-2018-1285. |
1Knime 1Knime Analytics Platform Jun 17, 2026 Dec 16, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 KNIME Analytics Platform before 4.5.0 is vulnerable to XXE (external XML entity injection) via a crafted workflow file (.knwf), aka AP-17730. |
dbeaver is vulnerable to Improper Restriction of XML External Entity Reference |
The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML class object, when it receives parsed string data from org.h2.jdbc.JdbcRe...Show more |
National Library of the Netherlands multiNER <= c0440948057afc6e3d6b4903a7c05e666b94a3bc is affected by an XML External Entity (XXE) vulnerability in multiNER/ner.py. Since XML parsing resolves external entities, a malic...Show more |
National Library of the Netherlands digger < 6697d1269d981e35e11f240725b16401b5ce3db5 is affected by a XML External Entity (XXE) vulnerability. Since XML parsing resolves external entities, a malicious XML stream could l...Show more |
CloverDX Server before 5.11.2 and and 5.12.x before 5.12.1 allows XXE during configuration import. |
1Claris 2Filemaker Pro Filemaker ServerJun 17, 2026 Nov 22, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An XML External Entity issue in Claris FileMaker Pro and Server (including WebDirect) before 19.4.1 allows a remote attacker to disclose local files via a crafted XML/Excel document and perform server-side request forger...Show more |
1Jenkins 1Owasp Dependency Check Jun 17, 2026 Nov 12, 2021 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 Jenkins OWASP Dependency-Check Plugin 5.1.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |