← Back
CWE-611

1,303 CVEs • Abstraction: Base

Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

JSON object

Loading...

CVEs (1,303)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Pom2config
Jun 17, 2026
Nov 12, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Jenkins pom2config Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers with Overall/Read and Item/Read permissions to have Jenkins parse a crafted XML...Show more
Jenkins pom2config Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers with Overall/Read and Item/Read permissions to have Jenkins parse a crafted XML file that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery.Show less
1Jenkins
1Performance
Jun 17, 2026
Nov 12, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Performance Plugin 3.20 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
1Fortinet
1Fortiportal
Jun 17, 2026
Nov 2, 2021
N/A· v4
8.1 HIGH· v3
6.4 MEDIUM· v2
An improper restriction of XML external entity reference vulnerability in the parser of XML responses of FortiPortal before 6.0.6 may allow an attacker who controls the producer of XML reports consumed by FortiPortal to...Show more
An improper restriction of XML external entity reference vulnerability in the parser of XML responses of FortiPortal before 6.0.6 may allow an attacker who controls the producer of XML reports consumed by FortiPortal to trigger a denial of service or read arbitrary files from the underlying file system by means of specifically crafted XML documents.Show less
1Antennahouse
1Office Server Document Converter
Jun 17, 2026
Nov 1, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Entity (XXE) attack to cause a denial of service (DoS) condition to the oth...Show more
Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Entity (XXE) attack to cause a denial of service (DoS) condition to the other servers by processing a specially crafted XML document.Show less
1Antennahouse
1Office Server Document Converter
Jun 17, 2026
Nov 1, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Entity (XXE) attack to cause a denial of service (DoS) condition by process...Show more
Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Entity (XXE) attack to cause a denial of service (DoS) condition by processing a specially crafted XML document.Show less
1Easyxml Project
1Easyxml
Jun 17, 2026
Oct 31, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The parseXML function in Easy-XML 0.5.0 was discovered to have a XML External Entity (XXE) vulnerability which allows for an attacker to expose sensitive data or perform a denial of service (DOS) via a crafted external e...Show more
The parseXML function in Easy-XML 0.5.0 was discovered to have a XML External Entity (XXE) vulnerability which allows for an attacker to expose sensitive data or perform a denial of service (DOS) via a crafted external entity entered into the XML content as input.Show less
1Getsymphony
1Symphony
Jul 9, 2026
Oct 31, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).
1Modx
1Modx Revolution
Jun 17, 2026
Oct 31, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).
1Stanford
1Corenlp
Jun 17, 2026
Oct 19, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
corenlp is vulnerable to Improper Restriction of XML External Entity Reference
1Stanford
1Corenlp
Jun 17, 2026
Oct 15, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
corenlp is vulnerable to Improper Restriction of XML External Entity Reference
1S Cms
1S Cms
Jun 17, 2026
Oct 14, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read arbitrary files.
1Cybozu
1Remote Service Manager
Jun 17, 2026
Oct 13, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to conduct XML External Entity (XXE) attacks and obtain the information stored in the product via unspecified vectors. This issue occurs only wh...Show more
Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to conduct XML External Entity (XXE) attacks and obtain the information stored in the product via unspecified vectors. This issue occurs only when using Mozilla Firefox.Show less
1Tibco
1Jasperreports Server
Jun 17, 2026
Oct 12, 2021
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
The XMLA Connections component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBC...Show more
The XMLA Connections component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for ActiveMatrix BPM, and TIBCO JasperReports Server for Microsoft Azure contains a difficult to exploit vulnerability that allows a low privileged attacker with network access to interfere with XML processing in the affected component. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: versions 7.2.1 and below, TIBCO JasperReports Server: versions 7.5.0 and 7.5.1, TIBCO JasperReports Server: version 7.8.0, TIBCO JasperReports Server: version 7.9.0, TIBCO JasperReports Server - Community Edition: versions 7.8.0 and below, TIBCO JasperReports Server - Developer Edition: versions 7.9.0 and below, TIBCO JasperReports Server for AWS Marketplace: versions 7.9.0 and below, TIBCO JasperReports Server for ActiveMatrix BPM: versions 7.9.0 and below, and TIBCO JasperReports Server for Microsoft Azure: version 7.8.0.Show less
1Sap
1Businessobjects Business Intelligence Platform
Jun 17, 2026
Oct 12, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SAP BusinessObjects Business Intelligence Platform (Crystal Reports) - versions 420, 430, allows an unauthenticated attacker to exploit missing XML validations at endpoints to read sensitive data. These endpoints are nor...Show more
SAP BusinessObjects Business Intelligence Platform (Crystal Reports) - versions 420, 430, allows an unauthenticated attacker to exploit missing XML validations at endpoints to read sensitive data. These endpoints are normally exposed over the network and successful exploitation can enable the attacker to retrieve arbitrary files from the server.Show less
1Alkacon
1Opencms
Jun 17, 2026
Oct 8, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfiltrate files from the server's file system by uploading a crafted SVG do...Show more
An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfiltrate files from the server's file system by uploading a crafted SVG document.Show less
1Zohocorp
1Manageengine Admanager Plus
Jun 17, 2026
Oct 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE.
1Apache
1Openoffice
Jun 17, 2026
Oct 7, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Apache OpenOffice has a dependency on expat software. Versions prior to 2.1.0 were subject to CVE-2013-0340 a "Billion Laughs" entity expansion denial of service attack and exploit via crafted XML files. ODF files consis...Show more
Apache OpenOffice has a dependency on expat software. Versions prior to 2.1.0 were subject to CVE-2013-0340 a "Billion Laughs" entity expansion denial of service attack and exploit via crafted XML files. ODF files consist of a set of XML files. All versions of Apache OpenOffice up to 4.1.10 are subject to this issue. expat in version 4.1.11 is patched.Show less
1Pingidentity
1Pingfederate
Jun 17, 2026
Oct 7, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure.
1Cisco
1Identity Services Engine
Jun 17, 2026
Oct 6, 2021
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information or conduct a server-side request forgery (SSRF)...Show more
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information or conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing certain XML files. An attacker could exploit this vulnerability by uploading a crafted XML file that contains references to external entities. A successful exploit could allow the attacker to retrieve files from the local system, resulting in the disclosure of sensitive information, or cause the web application to perform arbitrary HTTP requests on behalf of the attacker.Show less
1Netscout
1Ngeniusone
Jun 17, 2026
Sep 30, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
NEI in NETSCOUT nGeniusONE 6.3.0 build 1196 allows XML External Entity (XXE) attacks.