CWE-611

Improper Restriction of XML External Entity Reference

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

1,228 vulnerabilities with CWE-611
CVE-2026-6807 MEDIUM
NSA GRASSMARLIN Improper Restriction of XML External Entity Reference
CVSS 5.5
CVE-2026-41066 HIGH
lxml <6.1.0 - Info Disclosure
CVSS 7.5
CVE-2026-40882 HIGH
OpenRemote has XXE in Velbus Asset Import
CVSS 7.6
CVE-2026-26171 HIGH
.NET Denial of Service Vulnerability
CVSS 7.5
CVE-2026-33737 MEDIUM
Chamilo LMS has an XML External Entity (XXE) Injection
CVSS 5.3
CVE-2026-4374 CRITICAL
RTI Connext Professional Multiple Services - XXE
CVSS 9.1
CVE-2026-34401 MEDIUM
XML Notepad: XML External Entity (XXE) Injection via Unsafe XmlTextReader in XML Diff and Schema Loading
CVSS 6.5
CVE-2026-29924 HIGH
Grav CMS <1.7.x - XXE
CVSS 7.6
CVE-2026-4980 MEDIUM
Improper Restriction of XML External Entity Reference in Inkscape
CVSS 6.3
CVE-2026-33913 HIGH
OpenEMR: XInclude Injection in CCDA Import Allows Reading Arbitrary Server Files
CVSS 7.7
CVE-2026-28809 MEDIUM
XXE in esaml SAML library allows local file read and potential SSRF
CVE-2026-33371 MEDIUM
Zimbra Collaboration 10.0-10.1 - XXE
CVSS 4.3
CVE-2026-3511 HIGH
Slovensko.digital Autogram < 2.7.2 - SSRF
CVSS 8.6
CVE-2026-32251 MEDIUM
Tolgee <3.166.3 - XXE
CVSS 6.5
CVE-2026-1567 HIGH
IBM InfoSphere Information Server 11.7.0.0-11.7.1.6 - Info Disclosure
CVSS 7.1
CVE-2026-3404 MEDIUM
thinkgem JeeSite <=5.15.1 - XXE
CVSS 5.0
CVE-2026-2252 HIGH
Xerox FreeFlow Core <=8.0.7 - XXE/SSRF
CVSS 7.5
CVE-2026-2536 MEDIUM
opencc JFlow <20260129 - XXE
CVSS 6.3
CVE-2026-1227 HIGH
EBO - Info Disclosure
CVE-2026-2074 MEDIUM
O2OA <9.0.0 - SSRF
CVSS 6.3
CVE-2026-23739 LOW
Asterisk <20.7-cert9, 20.18.2, 21.12.1, 22.8.2, 23.2.2 - Info Discl...
CVSS 2.0
CVE-2026-23795 MEDIUM
Apache Syncope <3.0.15/<4.0.3 - XML External Entity Reference
CVSS 4.9
CVE-2026-21569 HIGH
Atlassian Crowd < 7.1.3 - XXE
CVSS 7.9
CVE-2026-24400 CRITICAL
AssertJ <3.27.7 - XSS
CVSS 9.1
CVE-2026-1218 MEDIUM
Bjskzy Zhiyou ERP <11.0 - XML External Entity Reference
CVSS 6.3
Details
Vulnerabilities 1,228