CWE-611— Improper Restriction of XML External Entity Reference (XXE)
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.— MITRE CWE catalog
1,298 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-611page 1 of 26
- CVE-2005-1306HIGHCVSS 7.5EG 7.52005-06-15
The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the "XML External Entity vulnerability."
- CVE-2009-1699HIGHCVSS 7.5EG 7.52009-06-10
The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote attackers to read arbit…
- CVE-2010-2245HIGHCVSS 7.4EG 7.42017-08-08
XML External Entity (XXE) vulnerability in Apache Wink 1.1.1 and earlier allows remote attackers to read arbitrary files or cause a denial of service via a crafted XML document.
- CVE-2010-3322HIGHCVSS 8.8EG 8.82010-09-14
The XML parser in Splunk 4.0.0 through 4.1.4 allows remote authenticated users to obtain sensitive information and gain privileges via an XML External Entity (XXE) attack to unknown vectors.
- CVE-2011-3600HIGHCVSS 7.5EG 7.52019-11-26
The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with executable payloads that discloses the contents of files in the filesystem. In addition, it c…
- CVE-2012-0037MEDIUMCVSS 6.5EG 6.52012-06-17
Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML exter…
- CVE-2012-1102HIGHCVSS 7.5EG 7.52021-07-09
It was discovered that the XML::Atom Perl module before version 0.39 did not disable external entities when parsing XML from potentially untrusted sources. This may allow attackers to gain read access to otherwise protected resources, depe…
- CVE-2012-2239CRITICALCVSS 9.1EG 9.12012-11-24
Mahara 1.4.x before 1.4.4 and 1.5.x before 1.5.3 allows remote attackers to read arbitrary files or create TCP connections via an XML external entity (XXE) injection attack, as demonstrated by reading config.php.
- CVE-2012-2656HIGHCVSS 7.5EG 7.52019-12-18
An XML eXternal Entity (XXE) issue exists in Restlet 1.1.10 in an endpoint using XML transport, which lets a remote attacker obtain sensitive information.
- CVE-2012-3489MEDIUMCVSS 6.5EG 6.52012-10-03
The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary…
- CVE-2012-5656MEDIUMCVSS 5.5EG 5.52013-01-18
The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.
- CVE-2013-0340MEDIUMCVSS v2 6.8EG 6.82014-01-21
expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP…
- CVE-2013-1824MEDIUMCVSS v2 4.3EG 4.32013-09-16
The SOAP parser in PHP before 5.3.22 and 5.4.x before 5.4.12 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML Exte…
- CVE-2013-1915HIGHCVSS v2 7.5EG 7.52013-04-25
ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entit…
- CVE-2013-4333CRITICALCVSS 9.1EG 9.12020-01-24
OpenPNE 3 versions 3.8.7, 3.6.11, 3.4.21.1, 3.2.7.6, 3.0.8.5 has an External Entity Injection Vulnerability
- CVE-2013-4334CRITICALCVSS 9.8EG 9.82020-02-07
opWebAPIPlugin 0.5.1, 0.4.0, and 0.1.0: XXE Vulnerabilities
- CVE-2014-0030CRITICALCVSS 9.8EG 9.82017-10-10
The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.
- CVE-2014-0225HIGHCVSS 8.8EG 8.82017-05-25
When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an X…
- CVE-2014-0931CRITICALCVSS 9.1EG 9.12018-04-20
Multiple XML external entity (XXE) vulnerabilities in the (1) CCRC WAN Server / CM Server, (2) Perl CC/CQ integration trigger scripts, (3) CMAPI Java interface, (4) ClearCase remote client, and (5) CMI and OSLC-based ClearQuest integration…
- CVE-2014-0950HIGHCVSS 7.1EG 7.12018-04-20
Multiple XML external entity (XXE) vulnerabilities in (1) CQWeb / CM Server, (2) ClearQuest Native client, (3) ClearQuest Eclipse client, and (4) ClearQuest Eclipse Designer components in IBM Rational ClearQuest 7.1.1 through 7.1.1.9, 7.1.…
- CVE-2014-125087MEDIUMCVSS 5.5EG 5.52023-02-19
A vulnerability was found in java-xmlbuilder up to 1.1. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to xml external entity reference. Upgrading to version 1.2 is able to ad…
- CVE-2014-2052CRITICALCVSS 9.8EG 9.82020-02-11
Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
- CVE-2014-2296HIGHCVSS 8.8EG 8.82018-07-20
XML external entity (XXE) vulnerability in java/org/jasig/cas/util/SamlUtils.java in Jasig CAS server before 3.4.12.1 and 3.5.x before 3.5.2.1, when Google Accounts Integration is enabled, allows remote unauthenticated users to bypass auth…
- CVE-2014-3005CRITICALCVSS 9.8EG 9.82018-02-01
XML external entity (XXE) vulnerability in Zabbix 1.8.x before 1.8.21rc1, 2.0.x before 2.0.13rc1, 2.2.x before 2.2.5rc1, and 2.3.x before 2.3.2 allows remote attackers to read arbitrary files or potentially execute arbitrary code via a cra…
- CVE-2014-3242MEDIUMCVSS v2 5.0EG 5.02014-05-12
SOAPpy 0.12.5 allows remote attackers to read arbitrary files via a SOAP request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
- CVE-2014-3244CRITICALCVSS 9.8EG 9.82018-02-01
XML external entity (XXE) vulnerability in the RSSDashlet dashlet in SugarCRM before 6.5.17 allows remote attackers to read arbitrary files or potentially execute arbitrary code via a crafted DTD in an XML request.
- CVE-2014-3579CRITICALCVSS 9.8EG 9.82017-10-27
XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
- CVE-2014-3599MEDIUMCVSS 6.5EG 6.52019-11-12
HornetQ REST is vulnerable to XML External Entity due to insecure configuration of RestEasy
- CVE-2014-3600CRITICALCVSS 9.8EG 9.82017-10-27
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
- CVE-2014-3630CRITICALCVSS 9.8EG 9.82017-12-29
XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow remote attackers to read arbitrary files, cause a denial of service, or have unspecified other impact …
- CVE-2014-3643HIGHCVSS 7.5EG 7.52019-12-15
jersey: XXE via parameter entities not disabled by the jersey SAX parser
- CVE-2014-3990CRITICALCVSS 9.8EG 9.82018-03-20
The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and earlier allows remote attackers to conduct server-side request forgery (SSRF) attacks or possibly conduct XML External Entity (XXE) attacks and execute arbitra…
- CVE-2014-5238HIGHCVSS 7.8EG 7.82020-01-14
XML external entity (XXE) vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev11 and 7.6.x before 7.6.0-rev9 allows remote attackers to read arbitrary files and possibly other unspecified impact via a crafted OpenDocument Text docu…
- CVE-2014-9487CRITICALCVSS 9.8EG 9.82017-10-17
The getid3 library in MediaWiki before 1.24.1, 1.23.8, 1.22.15 and 1.19.23 allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack. NOTE: Related to…
- CVE-2015-0194MEDIUMCVSS 6.5EG 6.52017-08-02
XML External Entity (XXE) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and IBM Sterling File Gateway 2.1 and 2.2 allows remote attackers to read arbitrary files via a crafted XML data.
- CVE-2015-10029MEDIUMCVSS 5.5EG 5.52023-01-07
A vulnerability classified as problematic was found in kelvinmo simplexrd up to 3.1.0. This vulnerability affects unknown code of the file simplexrd/simplexrd.class.php. The manipulation leads to xml external entity reference. Upgrading to…
- CVE-2015-10082CRITICALCVSS 5.5EG 9.82023-02-21
A vulnerability classified as problematic has been found in UIKit0 libplist 1.12. This affects the function plist_from_xml of the file src/xplist.c of the component XML Handler. The manipulation leads to xml external entity reference. The …
- CVE-2015-1809HIGHCVSS 7.5EG 7.52020-01-15
XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via an XPath query.
- CVE-2015-1811HIGHCVSS 7.5EG 7.52020-01-15
XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via a crafted XML document.
- CVE-2015-1832CRITICALCVSS 9.1EG 9.12016-10-03
XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows context-dependent attackers to read arbitrary files or cause a denial of service (resourc…
- CVE-2015-3160MEDIUMCVSS 4.3EG 4.32017-09-06
XML external entity (XXE) vulnerability in bkr/server/jobs.py in Beaker before 20.1 allows remote authenticated users to obtain sensitive information via submitting job XML to the server containing entity references which reference files f…
- CVE-2015-3907CRITICALCVSS 9.8EG 9.82019-07-03
CodeIgniter Rest Server (aka codeigniter-restserver) 2.7.1 allows XXE attacks.
- CVE-2015-7241CRITICALCVSS 9.8EG 9.82017-09-06
XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.
- CVE-2015-7273CRITICALCVSS 9.8EG 9.82017-04-10
Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has XXE.
- CVE-2015-7326CRITICALCVSS 9.8EG 9.82017-06-07
XML External Entity (XXE) vulnerability in Milton Webdav before 2.7.0.3.
- CVE-2015-7461MEDIUMCVSS 6.5EG 6.52018-03-20
XML external entity (XXE) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote authenticated users to cause a denial of service (memory consumption) via crafted XML data. IBM X-Force ID: 108357.
- CVE-2015-7743MEDIUMCVSS 6.5EG 6.52017-01-23
XML external entity vulnerability in PRTG Network Monitor before 16.2.23.3077/3078 allows remote authenticated users to read arbitrary files by creating a new HTTP XML/REST Value sensor that accesses a crafted XML file.
- CVE-2015-7968MEDIUMCVSS 4.3EG 4.32020-03-09
nwbc_ext2int in SAP NetWeaver Application Server before Security Note 2183189 allows XXE attacks for local file inclusion via the sap/bc/ui2/nwbc/nwbc_ext2int/ URI.
- CVE-2015-8031CRITICALCVSS 9.8EG 9.82022-07-18
Hudson (aka org.jvnet.hudson.main:hudson-core) before 3.3.2 allows XXE attacks.
- CVE-2015-8549HIGHCVSS 7.1EG 7.12020-01-15
XML external entity (XXE) vulnerability in PyAMF before 0.8.0 allows remote attackers to cause a denial of service or read arbitrary files via a crafted Action Message Format (AMF) payload.
Map vulnerabilities like CWE-611 to your infrastructure
EchelonGraph correlates every CVE — across CWE-611 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →