CWE-611

Improper Restriction of XML External Entity Reference

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

1,209 vulnerabilities with CWE-611
CVE-2026-1567 HIGH
IBM InfoSphere Information Server 11.7.0.0-11.7.1.6 - Info Disclosure
CVSS 7.1
CVE-2026-3404 MEDIUM
thinkgem JeeSite <=5.15.1 - XXE
CVSS 5.0
CVE-2026-2252 HIGH
Xerox FreeFlow Core <=8.0.7 - XXE/SSRF
CVSS 7.5
CVE-2025-36247 HIGH
IBM Db2 11.5.0-11.5.9/12.1.0-12.1.3 - XXE
CVSS 7.1
CVE-2026-2536 MEDIUM
opencc JFlow <20260129 - XXE
CVSS 6.3
CVE-2020-37192 MEDIUM
MSN Password Recovery 1.30 - Info Disclosure
CVSS 6.2
CVE-2026-1227
EBO - Info Disclosure
CVE-2026-2074 MEDIUM
O2OA <9.0.0 - SSRF
CVSS 6.3
CVE-2026-23739 LOW
Asterisk <20.7-cert9, 20.18.2, 21.12.1, 22.8.2, 23.2.2 - Info Discl...
CVSS 2.0
CVE-2026-23795 MEDIUM
Apache Syncope <3.0.15/<4.0.3 - XML External Entity Reference
CVSS 4.9
CVE-2026-21569 HIGH
Atlassian Crowd < 7.1.3 - XXE
CVSS 7.9
CVE-2026-24400 CRITICAL
AssertJ <3.27.7 - XSS
CVSS 9.1
CVE-2025-65482 CRITICAL
Opensagres Xdocreport < 2.0.3 - XXE
CVSS 9.8
CVE-2026-1218 MEDIUM
Bjskzy Zhiyou ERP <11.0 - XML External Entity Reference
CVSS 6.3
CVE-2025-14478 HIGH
Demo Importer Plus <2.0.9 - Authenticated RCE
CVSS 7.5
CVE-2022-50899 MEDIUM
Geonetwork 3.10-4.2.0 - SSRF
CVSS 6.5
CVE-2025-68493 HIGH
Apache Struts <6.1.0 - XML Validation
CVSS 8.1
CVE-2026-22186 HIGH
OME Pom-bio-formats - XXE
CVSS 7.1
CVE-2026-20029 MEDIUM
Cisco ISE - Info Disclosure
CVSS 4.9
CVE-2025-36589 HIGH
Dell Unisphere For Powermax < 9.2.4.19 - XXE
CVSS 7.6
CVE-2025-68280 MEDIUM
Apache Spatial Information System < 1.5 - XXE
CVSS 6.5
CVE-2025-15251 MEDIUM
beecue FastBee <2.1 - XML External Entity Reference
CVSS 5.6
CVE-2019-25253 HIGH
KYOCERA Net Admin 3.4.0906 - XXE Injection
CVSS 7.5
CVE-2018-25142 CRITICAL
NovaRad NovaPACS Diagnostics Viewer <8.5.19.75 - XXE Injection
CVSS 9.8
CVE-2024-58335 MEDIUM
OpenXRechnungToolbox <6c50e89 - XML External Entity
CVSS 5.0
Details
Vulnerabilities 1,209