CWE-611

Improper Restriction of XML External Entity Reference

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

1,250 vulnerabilities with CWE-611
CVE-2026-49875 CRITICAL
Apache CXF: XML External Entity (XXE) Injection in W3CMultiSchemaFactory and EndpointReferenceUtils
CVSS 9.8
CVE-2026-40998 HIGH
Spring Web Services - Jaxp13 XPath XXE via StreamSource and SAXSource
CVSS 8.2
CVE-2026-40991 MEDIUM
XML External Entity (XXE) injection when documenting untrusted XML content
CVSS 5.9
CVE-2026-47960 HIGH
ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
CVSS 7.4
CVE-2026-8045 HIGH
Schneider Electric EcoStruxure™ IT Data Center Expert - Improper Restriction of XML External Entity Reference
CVE-2026-49383 LOW
Jetbrains IntelliJ Idea < 2026.1 - Improper Restriction of XML External Entity Reference
CVSS 3.3
CVE-2026-2253 HIGH
Hitachi Vantara Pentaho Data Integration & Analytics - Improper Restriction of XML External Entity Reference
CVSS 7.7
CVE-2026-3603 HIGH
IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML external entity injection (XXE) attack
CVSS 7.1
CVE-2026-44618 MEDIUM
Apache CXF: XXE vulnerability in WS-Transfer functionality
CVSS 5.3
CVE-2026-46722 MEDIUM
XML External Entity Injection in extension "Faceted Search" (ke_search)
CVE-2026-39053 MEDIUM
Oinone Pamirs 7.0.0 - XML External Entity Injection
CVSS 6.5
CVE-2026-44445 MEDIUM
ERPNext: XML External Entity (XEE) Reference Vulnerability in the EDI Module
CVSS 6.5
CVE-2026-41895 HIGH
changedetection.io: XXE vulnerability in the changedetection.io project
CVSS 7.5
CVE-2026-42212 HIGH
SolidCAM-GPPL-IDE: XML External Entity (XXE) and billion-laughs DoS in VMID parser
CVE-2026-41936 HIGH
Vvveb < 1.0.8.2 XML External Entity Injection via Import
CVSS 8.1
CVE-2026-38429 CRITICAL
OpenCMS v20 - XML External Entity Injection
CVSS 9.8
CVE-2026-40682 CRITICAL
Apache OpenNLP: XXE via Dictionary Parsing in DictionaryEntryPersistor
CVSS 9.1
CVE-2026-6501 MEDIUM
ILM Informatique jOpenDocument < 1.5 - XML External Entity Injection
CVE-2026-36765 HIGH
SpringBlade 4.8.0 Report Designer - XML External Entity Injection
CVSS 8.8
CVE-2026-6807 MEDIUM
NSA GRASSMARLIN Improper Restriction of XML External Entity Reference
CVSS 5.5
CVE-2026-41066 HIGH
lxml < 6.1.0 - XML External Entity Injection via Default Parser Configuration
CVSS 7.5
CVE-2026-40882 HIGH
OpenRemote has XXE in Velbus Asset Import
CVSS 7.6
CVE-2026-26171 HIGH
Microsoft .NET and PowerShell - Resource Consumption Denial of Service
CVSS 7.5
CVE-2026-33737 MEDIUM
Chamilo LMS XML Parsing - XML External Entity Injection
CVSS 5.3
CVE-2026-4374 CRITICAL
RTI Connext Professional Multiple Services - XXE
CVSS 9.1
Details
Vulnerabilities 1,250