← Back
CWE-611

1,268 CVEs • Abstraction: Base

Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

JSON object

Loading...

CVEs (1,268)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Redhat
1Spacewalk
Jun 17, 2026
Feb 17, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api endpoint. An unauthenticated remote attacker could use this flaw to retrieve the content of certain...Show more
A flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api endpoint. An unauthenticated remote attacker could use this flaw to retrieve the content of certain files and trigger a denial of service, or in certain circumstances, execute arbitrary code on the Spacewalk server.Show less
1Lenovo
1Xclarity Administrator
Jun 17, 2026
Feb 14, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow information disclosure.
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Feb 12, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Missing XML validation vulnerability in the PAN-OS web interface on Palo Alto Networks PAN-OS software allows authenticated users to inject arbitrary XML that results in privilege escalation. This issue affects PAN-OS 8....Show more
Missing XML validation vulnerability in the PAN-OS web interface on Palo Alto Networks PAN-OS software allows authenticated users to inject arbitrary XML that results in privilege escalation. This issue affects PAN-OS 8.1 versions earlier than PAN-OS 8.1.12 and PAN-OS 9.0 versions earlier than PAN-OS 9.0.6. This issue does not affect PAN-OS 7.1, PAN-OS 8.0, or PAN-OS 9.1 or later versions.Show less
1Sap
1Netweaver Guided Procedures
Jun 17, 2026
Feb 12, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
SAP NetWeaver (Guided Procedures), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate an XML document input from a compromised admin, leading to Denial of Service.
1Jenkins
1Fitnesse
Jun 17, 2026
Feb 12, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Jenkins FitNesse Plugin 1.30 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.
1Jenkins
1Nunit
Jun 17, 2026
Feb 12, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Jenkins NUnit Plugin 0.25 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.
1Owncloud
2Owncloud
Owncloud Server
Mar 31, 2025
Feb 11, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE)...Show more
Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.Show less
1Tejimaya
1Opwebapiplugin
Nov 21, 2024
Feb 7, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
opWebAPIPlugin 0.5.1, 0.4.0, and 0.1.0: XXE Vulnerabilities
1Checkstyle
1Checkstyle
Jun 17, 2026
Jan 30, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XML External Entity (XXE) Injection due to an incomplete fix for CVE-2019-9658.
1Jenkins
1Websphere Deployer
Jun 17, 2026
Jan 29, 2020
N/A· v4
7.6 HIGH· v3
6.5 MEDIUM· v2
Jenkins WebSphere Deployer Plugin 1.6.1 and earlier does not configure the XML parser to prevent XXE attacks which can be exploited by a user with Job/Configure permissions.
1Ibm
1Security Access Manager
Jun 17, 2026
Jan 28, 2020
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
IBM Security Access Manager Appliance 9.0.7.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or...Show more
IBM Security Access Manager Appliance 9.0.7.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 172018.Show less
1Tejimaya
1Openpne
Nov 21, 2024
Jan 24, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
OpenPNE 3 versions 3.8.7, 3.6.11, 3.4.21.1, 3.2.7.6, 3.0.8.5 has an External Entity Injection Vulnerability
1Jenkins
1Cloudbees
Nov 21, 2024
Jan 15, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via a crafted XML document.
1Jenkins
1Cloudbees
Nov 21, 2024
Jan 15, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via an XPath query.
1Jenkins
1Robot Framework
Jun 17, 2026
Jan 15, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Jenkins Robot Framework Plugin 2.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing users with Job/Configure to have Jenkins parse crafted XML documents.
1Jetbrains
1Idetalk
Jun 17, 2026
Jan 15, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
JetBrains IDETalk plugin before version 193.4099.10 allows XXE
1Pyamf
1Pyamf
Nov 21, 2024
Jan 15, 2020
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
XML external entity (XXE) vulnerability in PyAMF before 0.8.0 allows remote attackers to cause a denial of service or read arbitrary files via a crafted Action Message Format (AMF) payload.
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
Jan 14, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
XML external entity (XXE) vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev11 and 7.6.x before 7.6.0-rev9 allows remote attackers to read arbitrary files and possibly other unspecified impact via a crafted Ope...Show more
XML external entity (XXE) vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev11 and 7.6.x before 7.6.0-rev9 allows remote attackers to read arbitrary files and possibly other unspecified impact via a crafted OpenDocument Text document.Show less
1Yet Another Java Service Wrapper Project
1Yet Another Java Service Wrapper
Jun 17, 2026
Jan 14, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other products, allows attackers to exfiltrate data from remote hosts and potentially cause denial-of-servi...Show more
An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other products, allows attackers to exfiltrate data from remote hosts and potentially cause denial-of-service.Show less
2Canonical
Mozilla
2Firefox
Ubuntu Linux
Jun 17, 2026
Jan 8, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
If an XML file is served with a Content Security Policy and the XML file includes an XSL stylesheet, the Content Security Policy will not be applied to the contents of the XSL stylesheet. If the XSL sheet e.g. includes J...Show more
If an XML file is served with a Content Security Policy and the XML file includes an XSL stylesheet, the Content Security Policy will not be applied to the contents of the XSL stylesheet. If the XSL sheet e.g. includes JavaScript, it would bypass any of the restrictions of the Content Security Policy applied to the XML document. This vulnerability affects Firefox < 72.Show less