CWE-611
1,303 CVEs • Abstraction: Base
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CVEs (1,303)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianYaws3Debian Linux Ubuntu LinuxYawsJun 17, 2026 Sep 9, 2020 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection. |
Jenkins Klocwork Analysis Plugin 2020.2.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
Jenkins Valgrind Plugin 0.28 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
2Mpxj Oracle2Mpxj Primavera UnifierJun 17, 2026 Aug 29, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components. |
An issue was discovered in Guest.migrate in virt/libvirt/guest.py in OpenStack Nova before 19.3.1, 20.x before 20.3.1, and 21.0.0. By performing a soft reboot of an instance that has previously undergone live migration,...Show more |
Maltego before 4.2.12 allows XXE attacks. |
1Wso2 5Api Manager Api Manager AnalyticsApi Microgateway+2 moreJun 17, 2026 Aug 21, 2020 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates. This affects API Manager through 3.0.0, API Manager Analytics 2.2.0 and 2.5.0, API Microgateway 2.2.0, Enterprise Integrato...Show more |
1Wso2 2Api Manager Api MicrogatewayJun 17, 2026 Aug 21, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks. |
1Moog 2Exvf5c 2 Firmware Exvp7c2 3 FirmwareJun 17, 2026 Aug 21, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Several XML External Entity (XXE) vulnerabilities in the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units allow remote unauthenticated users to read arbitrary files via a crafted Document Type Definition (DTD) in an XML requ...Show more |
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sens...Show more |
IBM Cognos Anaytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume mem...Show more |
IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information...Show more |
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authentication is not required to exploit this vulnerability. The specific flaw exi...Show more |
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authentication is not required to exploit this vulnerability. The specific flaw exi...Show more |
A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to...Show more |
1Ibm 2Sterling External Authentication Server Sterling Secure ProxyJun 17, 2026 Jul 16, 2020 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 IBM Sterling External Authentication Server 6.0.1, 6.0.0, 2.4.3.2, and 2.4.2 and IBM Sterling Secure Proxy 6.0.1, 6.0.0, 3.4.3, and 3.4.2 are vulnerable to an XML External Entity Injection (XXE) attack when processing XM...Show more |
1Inetsoftware 1I Net Clear Reports Jun 17, 2026 Jul 15, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 XXE injection can occur in i-net Clear Reports 2019 19.0.287 (Designer), as used in i-net HelpDesk and other products, when XML input containing a reference to an external entity is processed by a weakly configured XML p...Show more |
2Debian Eclipse2Debian Linux Web Tools PlatformJun 17, 2026 Jul 15, 2020 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or vali...Show more |
1Ibm 1Qradar Security Information And Event Manager Jun 17, 2026 Jul 14, 2020 N/A· v4 5.5 MEDIUM· v3 5.5 MEDIUM· v2 IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory re...Show more |
1Rockwellautomation 1Studio 5000 Logix Designer Jun 17, 2026 Jul 14, 2020 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 Rockwell Automation Logix Designer Studio 5000 Versions 32.00, 32.01, and 32.02 vulnerable to an xml external entity (XXE) vulnerability, which may allow an attacker to view hostnames or other resources from the program. |