← Back
CWE-611

1,268 CVEs • Abstraction: Base

Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

JSON object

Loading...

CVEs (1,268)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dotplant
1Dotplant2
Jun 17, 2026
Sep 18, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in DotPlant2 before 2020-09-14. In class Pay2PayPayment in payment/Pay2PayPayment.php, there is an XXE vulnerability in the checkResult function. The user input ($_POST['xml']) is used for simplex...Show more
An issue was discovered in DotPlant2 before 2020-09-14. In class Pay2PayPayment in payment/Pay2PayPayment.php, there is an XXE vulnerability in the checkResult function. The user input ($_POST['xml']) is used for simplexml_load_string without sanitization. NOTE: This vulnerability only affects products that are no longer supported by the maintainerShow less
1Yworks
1Yed
Jun 17, 2026
Sep 17, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
yWorks yEd Desktop before 3.20.1 allows XXE attacks via an XML or GraphML document.
1Apache
1Cocoon
Jun 17, 2026
Sep 11, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to access any file on the server system.
1Hyland
1Onbase
Jun 17, 2026
Sep 11, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows XXE attacks for read/write access to arbitrary files.
1Nec
1Expresscluster X
Jun 17, 2026
Sep 10, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1. Authentication is not required to exploit this vulnerability. The specific flaw exists wit...Show more
This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1. Authentication is not required to exploit this vulnerability. The specific flaw exists within the clpwebmc executable. Due to the improper restriction of XML External Entity (XXE) references, a specially-crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker can leverage this vulnerability to disclose information in the context of SYSTEM. Was ZDI-CAN-10801.Show less
3Canonical
DebianYaws
3Debian Linux
Ubuntu LinuxYaws
Jun 17, 2026
Sep 9, 2020
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.
1Jenkins
1Klocwork Analysis
Jun 17, 2026
Sep 1, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Klocwork Analysis Plugin 2020.2.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
1Jenkins
1Valgrind
Jun 17, 2026
Sep 1, 2020
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
Jenkins Valgrind Plugin 0.28 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
2Mpxj
Oracle
2Mpxj
Primavera Unifier
Jun 17, 2026
Aug 29, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components.
1Openstack
1Nova
Jun 17, 2026
Aug 26, 2020
N/A· v4
8.3 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in Guest.migrate in virt/libvirt/guest.py in OpenStack Nova before 19.3.1, 20.x before 20.3.1, and 21.0.0. By performing a soft reboot of an instance that has previously undergone live migration,...Show more
An issue was discovered in Guest.migrate in virt/libvirt/guest.py in OpenStack Nova before 19.3.1, 20.x before 20.3.1, and 21.0.0. By performing a soft reboot of an instance that has previously undergone live migration, a user may gain access to destination host devices that share the same paths as host devices previously referenced by the virtual machine on the source host. This can include block devices that map to different Cinder volumes at the destination than at the source. Only deployments allowing host-based connections (for instance, root and ephemeral devices) are affected.Show less
1Maltego
1Maltego
Jun 17, 2026
Aug 26, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Maltego before 4.2.12 allows XXE attacks.
1Wso2
5Api Manager
Api Manager AnalyticsApi Microgateway+2 more
Jun 17, 2026
Aug 21, 2020
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates. This affects API Manager through 3.0.0, API Manager Analytics 2.2.0 and 2.5.0, API Microgateway 2.2.0, Enterprise Integrato...Show more
The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates. This affects API Manager through 3.0.0, API Manager Analytics 2.2.0 and 2.5.0, API Microgateway 2.2.0, Enterprise Integrator 6.2.0 and 6.3.0, and Identity Server Analytics through 5.6.0.Show less
1Wso2
2Api Manager
Api Microgateway
Jun 17, 2026
Aug 21, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.
1Moog
2Exvf5c 2 Firmware
Exvp7c2 3 Firmware
Jun 17, 2026
Aug 21, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Several XML External Entity (XXE) vulnerabilities in the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units allow remote unauthenticated users to read arbitrary files via a crafted Document Type Definition (DTD) in an XML requ...Show more
Several XML External Entity (XXE) vulnerabilities in the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units allow remote unauthenticated users to read arbitrary files via a crafted Document Type Definition (DTD) in an XML request.Show less
1Ibm
1Urbancode Deploy
Jun 17, 2026
Aug 5, 2020
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sens...Show more
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 181848.Show less
1Ibm
1Cognos Analytics
Jun 17, 2026
Aug 3, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
IBM Cognos Anaytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume mem...Show more
IBM Cognos Anaytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 179156.Show less
1Ibm
1Maximo Asset Management
Jun 17, 2026
Jul 29, 2020
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information...Show more
IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 181484.Show less
1Veeam
1One Firmware
Jun 17, 2026
Jul 28, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authentication is not required to exploit this vulnerability. The specific flaw exi...Show more
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Reporter_ImportLicense class. Due to the improper restriction of XML External Entity (XXE) references, a specially crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker can leverage this vulnerability to disclose file contents in the context of SYSTEM. Was ZDI-CAN-10710.Show less
1Veeam
1One Firmware
Jun 17, 2026
Jul 28, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authentication is not required to exploit this vulnerability. The specific flaw exi...Show more
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSRSReport class. Due to the improper restriction of XML External Entity (XXE) references, a specially crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker can leverage this vulnerability to disclose file contents in the context of SYSTEM. Was ZDI-CAN-10709.Show less
1Cisco
1Sd Wan Firmware
Jun 17, 2026
Jul 16, 2020
N/A· v4
7.3 HIGH· v3
4.9 MEDIUM· v2
A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to...Show more
A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing certain XML files. An attacker could exploit this vulnerability by persuading a user to import a crafted XML file with malicious entries. A successful exploit could allow the attacker to read and write files within the affected application.Show less