An issue was discovered in weixin-java-tools v3.3.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file. NOTE: this issue exists because of an incomplete fix for CVE-2018-20318.
Loading...
Loading...
An issue was discovered in weixin-java-tools v3.3.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file. NOTE: this issue exists because of an incomplete fix for CVE-2018-20318.
January 4, 2019
September 12, 2025
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| com.github.binarywang:weixin-java-common | 1.3.4 ... 3.3.1.B (129 versions) | 3.3.2.B | — |
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
See which npm, PyPI, Go, and Maven packages are affected by CVE-2019-5312
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.