← Back
CWE-611

1,303 CVEs • Abstraction: Base

Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

JSON object

Loading...

CVEs (1,303)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Intel
1Quartus Prime
Jun 17, 2026
Feb 9, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Improper restriction of XML external entity reference in DSP Builder Pro for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an unauthenticated user to potentially enable information disclosure via ne...Show more
Improper restriction of XML external entity reference in DSP Builder Pro for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an unauthenticated user to potentially enable information disclosure via network access.Show less
1Signiant
1Manager+agents
Jun 17, 2026
Jan 30, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Signiant Manager+Agents before 15.1 allows XML External Entity (XXE) attacks.
1F5
3Big Ip Advanced Web Application Firewall
Big Ip Application Security ManagerBig Ip Fraud Protection Service
Jun 17, 2026
Jan 25, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
On BIG-IP FPS, ASM, and Advanced WAF versions 16.1.x before 16.1.1, 15.1.x before 15.1.4, and 14.1.x before 14.1.4.4, an XML External Entity (XXE) vulnerability exists in an undisclosed page of the F5 Advanced Web Applic...Show more
On BIG-IP FPS, ASM, and Advanced WAF versions 16.1.x before 16.1.1, 15.1.x before 15.1.4, and 14.1.x before 14.1.4.4, an XML External Entity (XXE) vulnerability exists in an undisclosed page of the F5 Advanced Web Application Firewall (Advanced WAF) and BIG-IP ASM Traffic Management User Interface (TMUI), also referred to as the Configuration utility, that allows an authenticated high-privileged attacker to read local files and force BIG-IP to send HTTP requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.Show less
1Ibm
1Cognos Controller
Jun 17, 2026
Jan 21, 2022
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information...Show more
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 190839.Show less
1Ibm
1Cognos Controller
Jun 17, 2026
Jan 21, 2022
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information...Show more
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 190838.Show less
1Jadx Project
1Jadx
Jun 17, 2026
Jan 20, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Improper Restriction of XML External Entity Reference in GitHub repository skylot/jadx prior to 1.3.2.
3Debian
NetappOracle
197 Mode Transition Tool
Active Iq Unified ManagerCloud Insights Acquisition Unit+16 more
Jun 17, 2026
Jan 19, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM E...Show more
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).Show less
1Stanford
1Corenlp
Jun 17, 2026
Jan 17, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
corenlp is vulnerable to Improper Restriction of XML External Entity Reference
1Adobe
2Experience Manager
Experience Manager Cloud Service
Jun 17, 2026
Jan 13, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) injection vulnerability that could be abused by an attacker to achieve RCE.
1Stanford
1Corenlp
Jun 17, 2026
Jan 13, 2022
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
corenlp is vulnerable to Improper Restriction of XML External Entity Reference
1Mitre
1Caldera
Jun 17, 2026
Jan 12, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in CALDERA 2.9.0. The Debrief plugin receives base64 encoded "SVG" parameters when generating a PDF document. These SVG documents are parsed in an unsafe manner and can be leveraged for XXE attack...Show more
An issue was discovered in CALDERA 2.9.0. The Debrief plugin receives base64 encoded "SVG" parameters when generating a PDF document. These SVG documents are parsed in an unsafe manner and can be leveraged for XXE attacks (e.g., File Exfiltration, Server Side Request Forgery, Out of Band Exfiltration, etc.).Show less
1Quest
1Kace Desktop Authority
Jun 17, 2026
Dec 22, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
XXE can occur in Quest KACE Desktop Authority before 11.2 because the log4net configuration file might be controlled by an attacker, a related issue to CVE-2018-1285.
1Knime
1Knime Analytics Platform
Jun 17, 2026
Dec 16, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
KNIME Analytics Platform before 4.5.0 is vulnerable to XXE (external XML entity injection) via a crafted workflow file (.knwf), aka AP-17730.
1Dbeaver
1Dbeaver
Jun 17, 2026
Dec 14, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
dbeaver is vulnerable to Improper Restriction of XML External Entity Reference
1H2database
1H2
Jun 17, 2026
Dec 10, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML class object, when it receives parsed string data from org.h2.jdbc.JdbcRe...Show more
The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML class object, when it receives parsed string data from org.h2.jdbc.JdbcResultSet.getSQLXML() method. If it executes the getSource() method when the parameter is DOMSource.class it will trigger the vulnerability.Show less
1Kb
1Multiner
Jun 17, 2026
Dec 8, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
National Library of the Netherlands multiNER <= c0440948057afc6e3d6b4903a7c05e666b94a3bc is affected by an XML External Entity (XXE) vulnerability in multiNER/ner.py. Since XML parsing resolves external entities, a malic...Show more
National Library of the Netherlands multiNER <= c0440948057afc6e3d6b4903a7c05e666b94a3bc is affected by an XML External Entity (XXE) vulnerability in multiNER/ner.py. Since XML parsing resolves external entities, a malicious XML stream could leak internal files and/or cause a DoS.Show less
1Kb
1Digger
Jun 17, 2026
Dec 8, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
National Library of the Netherlands digger < 6697d1269d981e35e11f240725b16401b5ce3db5 is affected by a XML External Entity (XXE) vulnerability. Since XML parsing resolves external entities, a malicious XML stream could l...Show more
National Library of the Netherlands digger < 6697d1269d981e35e11f240725b16401b5ce3db5 is affected by a XML External Entity (XXE) vulnerability. Since XML parsing resolves external entities, a malicious XML stream could leak internal files and/or cause a DoS.Show less
1Cloverdx
1Cloverdx
Jun 17, 2026
Dec 1, 2021
N/A· v4
7.7 HIGH· v3
6.8 MEDIUM· v2
CloverDX Server before 5.11.2 and and 5.12.x before 5.12.1 allows XXE during configuration import.
1Claris
2Filemaker Pro
Filemaker Server
Jun 17, 2026
Nov 22, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An XML External Entity issue in Claris FileMaker Pro and Server (including WebDirect) before 19.4.1 allows a remote attacker to disclose local files via a crafted XML/Excel document and perform server-side request forger...Show more
An XML External Entity issue in Claris FileMaker Pro and Server (including WebDirect) before 19.4.1 allows a remote attacker to disclose local files via a crafted XML/Excel document and perform server-side request forgery attacks.Show less
1Jenkins
1Owasp Dependency Check
Jun 17, 2026
Nov 12, 2021
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
Jenkins OWASP Dependency-Check Plugin 5.1.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.