CWE-611
1,268 CVEs • Abstraction: Base
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CVEs (1,268)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Apr 9, 2019 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0790, CVE-2019-07...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreJun 17, 2026 Apr 9, 2019 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0791, CVE-2019-07...Show more |
In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and the emulator position service (not part of the device distribution) could potentially be target of XX...Show more |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Apr 9, 2019 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. |
XXE issue in Airsonic before 10.1.2 during parse. |
IBM Sterling B2B Integrator Standard Edition 5.2.0 snf 6.0.0.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensiti...Show more |
The OAuthHelper in Atlassian Application Links before version 5.0.10, from version 5.1.0 before version 5.1.3, and from version 5.2.0 before version 5.2.6 used an XML document builder that was vulnerable to XXE when cons...Show more |
The administration backup restore resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to read files from the filesystem via a XXE vulnerability. |
Mitigates a XML External Entity Parsing issue in ArcSight Logger versions prior to 6.7. |
1Zohocorp 1Manageengine Servicedesk Plus Nov 21, 2024 Mar 25, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API. |
An XML External Entity Injection (XXE) vulnerability in the Management System (console) of BlackBerry AtHoc versions earlier than 7.6 HF-567 could allow an attacker to potentially read arbitrary local files from the appl...Show more |
An XXE issue was discovered in PHPSHE 1.7, which can be used to read any file in the system or scan the internal network without authentication. This occurs because of the call to wechat_getxml in include/plugin/payment/...Show more |
Nablarch 5 (5, and 5u1 to 5u13) allows remote attackers to conduct XML External Entity (XXE) attacks via unspecified vectors. |
1Sap 1Hana Extended Application Services Jun 17, 2026 Mar 12, 2019 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from an authenticated developer with privileges to the SAP space (XML External Entity vulnerability). |
3Checkstyle DebianFedoraproject3Checkstyle Debian LinuxFedoraJun 17, 2026 Mar 11, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Checkstyle before 8.18 loads external DTDs by default. |
1Cisco 1Iot Field Network Director Jun 17, 2026 Feb 21, 2019 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the web-based user interface of Cisco Internet of Things Field Network Director (IoT-FND) Software could allow an authenticated, remote attacker to gain read access to information that is stored on an...Show more |
1Ibm 1Infosphere Information Server Nov 21, 2024 Feb 15, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive i...Show more |
1Sap 5Advanced Business Application Programming Platform Kernel Advanced Business Application Programming Platform Krnl32nucAdvanced Business Application Programming Platform Krnl32uc+2 moreJun 17, 2026 Feb 15, 2019 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 SLD Registration of ABAP Platform allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. Fixed in versions KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT,KRNL32UC 7.2...Show more |
PMD 5.8.1 and earlier processes XML external entities in ruleset files it parses as part of the analysis process, allowing attackers tampering it (either by direct modification or MITM attacks when using remote rulesets)...Show more |
An XML external entity processing vulnerability exists in Jenkins Job Import Plugin 2.1 and earlier in src/main/java/org/jenkins/ci/plugins/jobimport/client/RestApiClient.java that allows attackers with the ability to co...Show more |