CWE-611
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
1,250 vulnerabilities with CWE-611
CVE-2026-49875
CRITICAL
Apache CXF: XML External Entity (XXE) Injection in W3CMultiSchemaFactory and EndpointReferenceUtils
CVSS 9.8
CVE-2026-40998
HIGH
Spring Web Services - Jaxp13 XPath XXE via StreamSource and SAXSource
CVSS 8.2
CVE-2026-40991
MEDIUM
XML External Entity (XXE) injection when documenting untrusted XML content
CVSS 5.9
CVE-2026-47960
HIGH
ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
CVSS 7.4
CVE-2026-8045
HIGH
Schneider Electric EcoStruxure™ IT Data Center Expert - Improper Restriction of XML External Entity Reference
CVE-2026-49383
LOW
Jetbrains IntelliJ Idea < 2026.1 - Improper Restriction of XML External Entity Reference
CVSS 3.3
CVE-2026-2253
HIGH
Hitachi Vantara Pentaho Data Integration & Analytics - Improper Restriction of XML External Entity Reference
CVSS 7.7
CVE-2026-3603
HIGH
IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML external entity injection (XXE) attack
CVSS 7.1
CVE-2026-44618
MEDIUM
Apache CXF: XXE vulnerability in WS-Transfer functionality
CVSS 5.3
CVE-2026-46722
MEDIUM
XML External Entity Injection in extension "Faceted Search" (ke_search)
CVE-2026-39053
MEDIUM
Oinone Pamirs 7.0.0 - XML External Entity Injection
CVSS 6.5
CVE-2026-44445
MEDIUM
ERPNext: XML External Entity (XEE) Reference Vulnerability in the EDI Module
CVSS 6.5
CVE-2026-41895
HIGH
changedetection.io: XXE vulnerability in the changedetection.io project
CVSS 7.5
CVE-2026-42212
HIGH
SolidCAM-GPPL-IDE: XML External Entity (XXE) and billion-laughs DoS in VMID parser
CVE-2026-41936
HIGH
Vvveb < 1.0.8.2 XML External Entity Injection via Import
CVSS 8.1
CVE-2026-38429
CRITICAL
OpenCMS v20 - XML External Entity Injection
CVSS 9.8
CVE-2026-40682
CRITICAL
Apache OpenNLP: XXE via Dictionary Parsing in DictionaryEntryPersistor
CVSS 9.1
CVE-2026-6501
MEDIUM
ILM Informatique jOpenDocument < 1.5 - XML External Entity Injection
CVE-2026-36765
HIGH
SpringBlade 4.8.0 Report Designer - XML External Entity Injection
CVSS 8.8
CVE-2026-6807
MEDIUM
NSA GRASSMARLIN Improper Restriction of XML External Entity Reference
CVSS 5.5
CVE-2026-41066
HIGH
lxml < 6.1.0 - XML External Entity Injection via Default Parser Configuration
CVSS 7.5
CVE-2026-40882
HIGH
OpenRemote has XXE in Velbus Asset Import
CVSS 7.6
CVE-2026-26171
HIGH
Microsoft .NET and PowerShell - Resource Consumption Denial of Service
CVSS 7.5
CVE-2026-33737
MEDIUM
Chamilo LMS XML Parsing - XML External Entity Injection
CVSS 5.3
CVE-2026-4374
CRITICAL
RTI Connext Professional Multiple Services - XXE
CVSS 9.1
Details
Vulnerabilities
1,250