CWE-611
1,268 CVEs • Abstraction: Base
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CVEs (1,268)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted JSON/XML input to a cgi/ajax/phrase URI. |
SRS Policy Manager 6.X is affected by an XML External Entity Injection (XXE) vulnerability due to a misconfigured XML parser that processes user-supplied DTD input without sufficient validation. A remote unauthenticated...Show more |
1Microfocus 1Solutions Business Manager Jun 17, 2026 Feb 26, 2021 N/A· v4 8.0 HIGH· v3 5.2 MEDIUM· v2 Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to XML External Entity Processing (XXE) on certain operations. |
Pelco Digital Sentry Server 7.18.72.11464 has an XML External Entity vulnerability (exploitable via the DTD parameter entities technique), resulting in disclosure and retrieval of arbitrary data on the affected node via...Show more |
1Ibm 1Websphere Application Server Jun 17, 2026 Feb 10, 2021 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive info...Show more |
openHAB is a vendor and technology agnostic open source automation software for your home. In openHAB before versions 2.5.12 and 3.0.1 the XML external entity (XXE) attack allows attackers in the same network as the open...Show more |
1Ibm 1Websphere Application Server Jun 17, 2026 Jan 26, 2021 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive info...Show more |
2Apache Netapp2Nutch Snap Creator FrameworkJun 17, 2026 Jan 25, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML external entity injection (also known as XXE) is a web security vulnerability...Show more |
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CA Arcserve D2D 16.5. Authentication is not required to exploit this vulnerability. The specific flaw exists withi...Show more |
1Microfocus 1Application Lifecycle Management Jun 17, 2026 Jan 19, 2021 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 XML External Entity Injection vulnerability in Micro Focus Application Lifecycle Management (Previously known as Quality Center) product. The vulnerability affects versions 12.x, 12.60 Patch 5 and earlier, 15.0.1 Patch 2...Show more |
OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input. This allows an attacker to inject arbitrary HTML or XML into embedding documents. |
1Siemens 2Jt2go Teamcenter VisualizationJun 17, 2026 Jan 12, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). When opening a specially crafted xml file, the application could disclose arbitrary files to remot...Show more |
The TIBCO EBX Add-on for Oracle Hyperion EPM, TIBCO EBX Data Exchange Add-on, and TIBCO EBX Insight Add-on components of TIBCO Software Inc.'s TIBCO EBX Add-ons contain a vulnerability that theoretically allows a low pri...Show more |
1Sap 1Enterprise Performance Management Jun 17, 2026 Jan 12, 2021 N/A· v4 4.4 MEDIUM· v3 3.6 LOW· v2 SAP EPM Add-in for Microsoft Office, version - 1010 and SAP EPM Add-in for SAP Analysis Office, version - 2.8, allows an authenticated attacker with user privileges to parse malicious XML files which could result in XXE-...Show more |
1Ibm 1Security Verify Privilege Manager Jun 17, 2026 Jan 8, 2021 N/A· v4 4.4 MEDIUM· v3 3.6 LOW· v2 IBM Security Verify Privilege Manager 10.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A local attacker could exploit this vulnerability to expose sensitive information or con...Show more |
Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (therefore, only available to the Manager role). |
Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role. |
2Debian Nokogiri2Debian Linux NokogiriJun 17, 2026 Dec 30, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are...Show more |
1Kronos 1Web Time And Attendance Jun 17, 2026 Dec 21, 2020 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 An XXE attack can occur in Kronos WebTA 5.0.4 when SAML is used. |
In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in the saml consumer store extension, which is vulnerable to XXE attacks. This has been fixed in Zimbra...Show more |