CWE-611
1,268 CVEs • Abstraction: Base
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CVEs (1,268)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 1Security Access Manager For Enterprise Single Sign On Jun 17, 2026 Aug 26, 2019 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensit...Show more |
The XML-RPC subsystem in Zenoss 2.5.3 allows XXE attacks that lead to unauthenticated information disclosure via port 9988. |
1Ibm 2Business Automation Workflow Business Process ManagerJun 17, 2026 Aug 20, 2019 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, and 19.0.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerab...Show more |
1Ibm 1Security Guardium Big Data Intelligence Jun 17, 2026 Aug 20, 2019 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 IBM Security Guardium Big Data Intelligence 4.0 (SonarG) is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive inf...Show more |
1Ibm 2Infosphere Global Name Management Infosphere Identity InsightJun 17, 2026 Aug 20, 2019 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 IBM InfoSphere Global Name Management 5.0 and 6.0 and IBM InfoSphere Identity Insight 8.1 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit t...Show more |
1Ibm 3Intelligent Operations Center Intelligent Operations Center For Emergency ManagementWater Operations For WaternamicsJun 17, 2026 Aug 20, 2019 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 IBM Intelligent Operations Center V5.1.0 through V5.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive info...Show more |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Aug 14, 2019 N/A· v4 5.5 MEDIUM· v3 5.0 MEDIUM· v2 A denial of service vulnerability exists when the XmlLite runtime (XmlLite.dll) improperly parses XML input. An attacker who successfully exploited this vulnerability could cause a denial of service against an XML applic...Show more |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Aug 14, 2019 N/A· v4 7.5 HIGH· v3 9.3 HIGH· v2 A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input. An attacker who successfully exploited the vulnerability could run malicious code remotely to take cont...Show more |
The XML parser, which is being used by SAP Enable Now, before version 1902, has not been hardened correctly, leading to Missing XML Validation vulnerability. This issue affects the file upload at multiple locations. An a...Show more |
1Zohocorp 1Manageengine Assetexplorer Jun 17, 2026 Aug 8, 2019 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Zoho ManageEngine AssetExplorer 6.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing license XML data. A remote attacker could exploit this vulnerability to expose sensitive information or...Show more |
An issue was discovered in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2. The Content.MainForm.wgx component is affected by XXE via a crafted XML document in POST data. There is potential...Show more |
The Transition Technologies "The Scheduler" app 5.1.3 for Jira allows XXE due to a weakly configured/parameterized XML parser. It was fixed in the versions 5.2.1 and 3.3.7 |
cPanel before 64.0.21 allows demo accounts to execute code via Encoding API calls (SEC-242). |
IBM Daeja ViewONE Professional, Standard & Virtual 5.0.5 and 5.0.6 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sen...Show more |
1Ibm 1I2 Intelligent Analysis Platform Jun 17, 2026 Jul 30, 2019 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 IBM i2 Intelligent Analyis Platform 9.0.0 through 9.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive info...Show more |
An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When sending an out-of-bounds XML document to a URL, it is possible to read the file structure and even the content of files without authentication. |
An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. With a valid administrator account, the "Move / Import / Export Users" screen has an Import Users option. This option accepts a ZIP archive containing...Show more |
5Apache AtlassianNetapp+2 more31Active Iq Unified Manager Apache Batik MapviewerBanking Enterprise Originations+28 moreJun 17, 2026 Jul 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description. |
1Mitsubishielectric 1Electric Fr Configurator2 Firmware Jun 17, 2026 Jul 26, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Mitsubishi Electric FR Configurator2, Version 1.16S and prior. This vulnerability is triggered when input passed to the XML parser is not sanitized while parsing the XML project and/or template file (.frc2). Once a user...Show more |
Vulnerability in the Oracle Hyperion Planning component of Oracle Hyperion (subcomponent: Security). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker...Show more |