CWE-611
1,303 CVEs • Abstraction: Base
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CVEs (1,303)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 1Websphere Application Server Jun 17, 2026 Apr 21, 2021 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive infor...Show more |
1Ibm 1Websphere Application Server Jun 17, 2026 Apr 20, 2021 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive informatio...Show more |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Apr 15, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP...Show more |
1Sap 1Netweaver Process Integration Jun 17, 2026 Apr 14, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In order to prevent XML External Entity vulnerability in SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - Enterprise Service Repository JAVA Mappings), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50, SAP...Show more |
The XML Import functionality of the Administration console in Perforce Helix ALM 2020.3.1 Build 22 accepts XML input data that is parsed by insecurely configured software components, leading to XXE attacks. |
1Forcepoint 3Data Loss Prevention Email SecurityWeb Security Content GatewayJun 17, 2026 Apr 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Forcepoint Web Security Content Gateway versions prior to 8.5.4 improperly process XML input, leading to information disclosure. |
1Proofpoint 1Insider Threat Management Jun 17, 2026 Apr 6, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is vulnerable to XML external entity (XXE) injection in the Web Console. The vulnerability requires admin user privileges and knowledge of the X...Show more |
2Fedoraproject Pikepdf Project2Fedora PikepdfJun 17, 2026 Apr 1, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries. |
1Ibm 6Engineering Insights Engineering Lifecycle ManagementEngineering Requirements Quality Assistant On Premises+3 moreJun 17, 2026 Mar 30, 2021 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 IBM Jazz Foundation Products are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory...Show more |
1Ibm 1Cloud Pak For Automation Jun 17, 2026 Mar 30, 2021 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 IBM Cloud Pak for Automation 20.0.2 and 20.0.3 IF002 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive inform...Show more |
MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. Affected versions: Mule 4.x runtime released b...Show more |
1Compassplus 1Tranzware E Commerce Payment Gateway Jun 17, 2026 Mar 19, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 /exec in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a vulnerability in its XML parser. |
A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP13), Solid Edge SE2021 (All Versions < SE2021MP3). When opening a specially crafted SEECTCXML file, the application could disclose arbitrar...Show more |
A remote authenticated authenticated xml external entity (xxe) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Due to improper restrictions on XML entities a vulnerability...Show more |
1Lumis 1Lumis Experience Platform Jun 17, 2026 Mar 3, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 LumisXP (aka Lumis Experience Platform) before 10.0.0 allows unauthenticated blind XXE via an API request to PageControllerXml.jsp. One can send a request crafted with an XXE payload and achieve outcomes such as reading...Show more |
EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted JSON/XML input to a cgi/ajax/phrase URI. |
SRS Policy Manager 6.X is affected by an XML External Entity Injection (XXE) vulnerability due to a misconfigured XML parser that processes user-supplied DTD input without sufficient validation. A remote unauthenticated...Show more |
1Microfocus 1Solutions Business Manager Jun 17, 2026 Feb 26, 2021 N/A· v4 8.0 HIGH· v3 5.2 MEDIUM· v2 Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to XML External Entity Processing (XXE) on certain operations. |
Pelco Digital Sentry Server 7.18.72.11464 has an XML External Entity vulnerability (exploitable via the DTD parameter entities technique), resulting in disclosure and retrieval of arbitrary data on the affected node via...Show more |
1Ibm 1Websphere Application Server Jun 17, 2026 Feb 10, 2021 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive info...Show more |