CWE-611
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
1,277 vulnerabilities with CWE-611
CVE-2026-54366
HIGH
CentreStack < 17.4 XXE via SharePoint Storage Configuration
CVSS 7.5
CVE-2026-50782
HIGH
Jinher OA C6 - Unauthenticated XML External Entity Injection via GetXmlHttp Endpoint
CVSS 7.5
CVE-2026-54082
MEDIUM
veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs
CVSS 6.5
CVE-2026-54079
HIGH
veraPDF Validation XXE via XFA
CVE-2026-54078
HIGH
veraPDF Validation XXE via Rich Text
CVE-2026-57917
MEDIUM
Improper Restriction of XML External Entity Reference in proCertum SmartSign
CVE-2026-56817
CRITICAL
Netty: XML External Entity (XXE) injection via unconfigured XML factory when DTD and entity processing are enabled
CVSS 9.8
CVE-2026-51080
CRITICAL
libpve-storage-perl 8.3.7 and 9.1.1 - XML External Entity Injection
CVSS 9.8
CVE-2026-8396
HIGH
XXE in Netcad's NetGIS
CVSS 7.5
CVE-2026-48359
CRITICAL
Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
CVSS 9.6
CVE-2026-45071
HIGH
Symfony: XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = true
CVSS 7.5
CVE-2026-54470
MEDIUM
Dell Unisphere For PowerMax - Improper Restriction of XML External Entity Reference
CVSS 5.3
CVE-2026-55471
CRITICAL
HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory
CVSS 9.1
CVE-2026-57259
MEDIUM
Foxit PDF Editor/Reader XDP XFA XXE arbitrary local file read
CVSS 6.5
CVE-2026-47898
CRITICAL
Apache Lucene.Net Analysis.Common PatternParser - XML External Entity Injection
CVSS 9.8
CVE-2026-13449
HIGH
XXE attack in IBM Business Automation Manager Open Editions
CVSS 7.6
CVE-2026-44018
MEDIUM
Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend
CVSS 5.5
CVE-2026-12975
HIGH
Red Hat Apicurio Registry 3 - XML External Entity Server-Side Request Forgery
CVSS 8.5
CVE-2026-57234
LOW
Nokogiri JRuby < 1.19.4 - NONET Bypass Allows Network Requests
CVSS 2.6
CVE-2026-44020
HIGH
Docling: Unsafe XML Entity Expansion in USPTO Patent Backend
CVSS 7.5
CVE-2026-56701
MEDIUM
Grav - XML External Entity Injection via SVG Upload
CVSS 6.5
CVE-2026-6653
CRITICAL
libxml2: Use after free in xmlParseInternalSubset via improper entity resolution handling
CVSS 9.8
CVE-2026-12788
MEDIUM
zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 XML Parser import xml external entity reference
CVSS 6.3
CVE-2026-48981
MEDIUM
pam_usb: xmlReadFile flags=0 permits XXE network entity fetching in conf.c
CVSS 6.7
CVE-2026-49875
CRITICAL
Apache CXF: XML External Entity (XXE) Injection in W3CMultiSchemaFactory and EndpointReferenceUtils
CVSS 9.8
Details
Vulnerabilities
1,277