CWE-611
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
1,209 vulnerabilities with CWE-611
CVE-2026-1567
HIGH
IBM InfoSphere Information Server 11.7.0.0-11.7.1.6 - Info Disclosure
CVSS 7.1
CVE-2026-3404
MEDIUM
thinkgem JeeSite <=5.15.1 - XXE
CVSS 5.0
CVE-2026-2252
HIGH
Xerox FreeFlow Core <=8.0.7 - XXE/SSRF
CVSS 7.5
CVE-2025-36247
HIGH
IBM Db2 11.5.0-11.5.9/12.1.0-12.1.3 - XXE
CVSS 7.1
CVE-2026-2536
MEDIUM
opencc JFlow <20260129 - XXE
CVSS 6.3
CVE-2020-37192
MEDIUM
MSN Password Recovery 1.30 - Info Disclosure
CVSS 6.2
CVE-2026-1227
EBO - Info Disclosure
CVE-2026-2074
MEDIUM
O2OA <9.0.0 - SSRF
CVSS 6.3
CVE-2026-23739
LOW
Asterisk <20.7-cert9, 20.18.2, 21.12.1, 22.8.2, 23.2.2 - Info Discl...
CVSS 2.0
CVE-2026-23795
MEDIUM
Apache Syncope <3.0.15/<4.0.3 - XML External Entity Reference
CVSS 4.9
CVE-2026-21569
HIGH
Atlassian Crowd < 7.1.3 - XXE
CVSS 7.9
CVE-2026-24400
CRITICAL
AssertJ <3.27.7 - XSS
CVSS 9.1
CVE-2025-65482
CRITICAL
Opensagres Xdocreport < 2.0.3 - XXE
CVSS 9.8
CVE-2026-1218
MEDIUM
Bjskzy Zhiyou ERP <11.0 - XML External Entity Reference
CVSS 6.3
CVE-2025-14478
HIGH
Demo Importer Plus <2.0.9 - Authenticated RCE
CVSS 7.5
CVE-2022-50899
MEDIUM
Geonetwork 3.10-4.2.0 - SSRF
CVSS 6.5
CVE-2025-68493
HIGH
Apache Struts <6.1.0 - XML Validation
CVSS 8.1
CVE-2026-22186
HIGH
OME Pom-bio-formats - XXE
CVSS 7.1
CVE-2026-20029
MEDIUM
Cisco ISE - Info Disclosure
CVSS 4.9
CVE-2025-36589
HIGH
Dell Unisphere For Powermax < 9.2.4.19 - XXE
CVSS 7.6
CVE-2025-68280
MEDIUM
Apache Spatial Information System < 1.5 - XXE
CVSS 6.5
CVE-2025-15251
MEDIUM
beecue FastBee <2.1 - XML External Entity Reference
CVSS 5.6
CVE-2019-25253
HIGH
KYOCERA Net Admin 3.4.0906 - XXE Injection
CVSS 7.5
CVE-2018-25142
CRITICAL
NovaRad NovaPACS Diagnostics Viewer <8.5.19.75 - XXE Injection
CVSS 9.8
CVE-2024-58335
MEDIUM
OpenXRechnungToolbox <6c50e89 - XML External Entity
CVSS 5.0
Details
Vulnerabilities
1,209