CWE-611
1,268 CVEs • Abstraction: Base
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CVEs (1,268)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
WSO2 Enterprise Integrator through 6.6.0 has an XXE vulnerability where a user (with admin console access) can use the XML validator to make unintended network invocations such as SSRF via an uploaded file. |
Jenkins Parasoft Findings Plugin 10.4.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
SAP Commerce, versions - 6.6, 6.7, 1808, 1811, 1905, does not process XML input securely in the Rest API from Servlet xyformsweb, leading to Missing XML Validation. This affects confidentiality and availability (partiall...Show more |
WebAccess/NMS (versions prior to 3.0.2) does not sanitize XML input. Specially crafted XML input could allow an attacker to read sensitive files. |
HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data |
An XXE issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request that contains malicious XML DTD data. |
Osmand through 2.0.0 allow XXE because of binary/BinaryMapIndexReader.java. |
Azkaban through 3.84.0 allows XXE, related to validator/XmlValidatorManager.java and user/XmlUserManager.java. |
Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java |
An XXE issue exists in Accenture Mercury before 1.12.28 because of the platformlambda/core/serializers/SimpleXmlParser.java component. |
Jenkins RapidDeploy Plugin 4.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
AutoUpdater.cs in AutoUpdater.NET before 1.5.8 allows XXE. |
The svglib package through 0.9.3 for Python allows XXE attacks via an svg2rlg call. |
1Sync 3Oxygen Xml Author Oxygen Xml DeveloperOxygen Xml EditorJun 17, 2026 Mar 16, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Oxygen XML Editor 21.1.1 allows XXE to read any file. |
1Zohocorp 1Manageengine Desktop Central Jun 17, 2026 Mar 11, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) atta...Show more |
1Johnsoncontrols 13Metasys Application And Data Server Metasys Extended Application And Data ServerMetasys Lonworks Control Server+10 moreJun 17, 2026 Mar 10, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 XXE vulnerability exists in the Metasys family of product Web Services which has the potential to facilitate DoS attacks or harvesting of ASCII server files. This affects Johnson Controls' Metasys Application and Data Se...Show more |
Jenkins Rundeck Plugin 3.6.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
Jenkins Cobertura Plugin 1.15 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
1Sap 1Netweaver Application Server Nov 21, 2024 Mar 9, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 nwbc_ext2int in SAP NetWeaver Application Server before Security Note 2183189 allows XXE attacks for local file inclusion via the sap/bc/ui2/nwbc/nwbc_ext2int/ URI. |
An issue was discovered in SmartClient 12.0. Unauthenticated exploitation of blind XXE can occur in the downloadWSDL feature by sending a POST request to /tools/developerConsoleOperations.jsp with a valid payload in the...Show more |