CWE-611
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
1,228 vulnerabilities with CWE-611
CVE-2026-6807
MEDIUM
NSA GRASSMARLIN Improper Restriction of XML External Entity Reference
CVSS 5.5
CVE-2026-41066
HIGH
lxml <6.1.0 - Info Disclosure
CVSS 7.5
CVE-2026-40882
HIGH
OpenRemote has XXE in Velbus Asset Import
CVSS 7.6
CVE-2026-26171
HIGH
.NET Denial of Service Vulnerability
CVSS 7.5
CVE-2026-33737
MEDIUM
Chamilo LMS has an XML External Entity (XXE) Injection
CVSS 5.3
CVE-2026-4374
CRITICAL
RTI Connext Professional Multiple Services - XXE
CVSS 9.1
CVE-2026-34401
MEDIUM
XML Notepad: XML External Entity (XXE) Injection via Unsafe XmlTextReader in XML Diff and Schema Loading
CVSS 6.5
CVE-2026-29924
HIGH
Grav CMS <1.7.x - XXE
CVSS 7.6
CVE-2026-4980
MEDIUM
Improper Restriction of XML External Entity Reference in Inkscape
CVSS 6.3
CVE-2026-33913
HIGH
OpenEMR: XInclude Injection in CCDA Import Allows Reading Arbitrary Server Files
CVSS 7.7
CVE-2026-28809
MEDIUM
XXE in esaml SAML library allows local file read and potential SSRF
CVE-2026-33371
MEDIUM
Zimbra Collaboration 10.0-10.1 - XXE
CVSS 4.3
CVE-2026-3511
HIGH
Slovensko.digital Autogram < 2.7.2 - SSRF
CVSS 8.6
CVE-2026-32251
MEDIUM
Tolgee <3.166.3 - XXE
CVSS 6.5
CVE-2026-1567
HIGH
IBM InfoSphere Information Server 11.7.0.0-11.7.1.6 - Info Disclosure
CVSS 7.1
CVE-2026-3404
MEDIUM
thinkgem JeeSite <=5.15.1 - XXE
CVSS 5.0
CVE-2026-2252
HIGH
Xerox FreeFlow Core <=8.0.7 - XXE/SSRF
CVSS 7.5
CVE-2026-2536
MEDIUM
opencc JFlow <20260129 - XXE
CVSS 6.3
CVE-2026-1227
HIGH
EBO - Info Disclosure
CVE-2026-2074
MEDIUM
O2OA <9.0.0 - SSRF
CVSS 6.3
CVE-2026-23739
LOW
Asterisk <20.7-cert9, 20.18.2, 21.12.1, 22.8.2, 23.2.2 - Info Discl...
CVSS 2.0
CVE-2026-23795
MEDIUM
Apache Syncope <3.0.15/<4.0.3 - XML External Entity Reference
CVSS 4.9
CVE-2026-21569
HIGH
Atlassian Crowd < 7.1.3 - XXE
CVSS 7.9
CVE-2026-24400
CRITICAL
AssertJ <3.27.7 - XSS
CVSS 9.1
CVE-2026-1218
MEDIUM
Bjskzy Zhiyou ERP <11.0 - XML External Entity Reference
CVSS 6.3
Details
Vulnerabilities
1,228