CWE-611

Improper Restriction of XML External Entity Reference

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

1,250 vulnerabilities with CWE-611
CVE-2023-28828 MEDIUM
Polarion ALM < V22R2 - XML External Entity Injection
CVSS 5.9
CVE-2023-25955 MEDIUM
National Land Numerical Information Data Conversion Tool - XML External Entity Injection
CVSS 5.5
CVE-2023-28340 MEDIUM
Zoho ManageEngine Applications Manager <= 16320 - Authenticated XML External Entity Injection
CVSS 6.5
CVE-2023-27876 HIGH
IBM TRIRIGA 4.0 - XML External Entity Injection
CVSS 7.1
CVE-2023-20030 MEDIUM
Cisco Identity Services Engine < 3.2 - Authenticated XML External Entity Injection via XML File Upload
CVSS 6.0
CVE-2023-28684 MEDIUM
Jenkins remote-jobs-view-plugin <0.0.3 - XXE
CVSS 6.5
CVE-2023-28683 HIGH
Jenkins Phabricator Differential Plugin <2.1.5 - XXE
CVSS 8.2
CVE-2023-28682 HIGH
Jenkins Performance Publisher Plugin <8.09 - XXE
CVSS 8.2
CVE-2023-28681 HIGH
Jenkins Visual Studio Code Metrics Plugin <1.7 - XXE
CVSS 8.2
CVE-2023-28680 HIGH
Jenkins Crap4J Plugin < 0.9 - XML External Entity Injection
CVSS 7.5
CVE-2023-28150 MEDIUM
Independentsoft JODF < 1.1.110 - XML External Entity Injection via Remote DTD in DOCX File
CVSS 5.3
CVE-2023-28151 MEDIUM
Independentsoft JSpreadsheet < 1.1.110 - XML External Entity Injection via DOCX File Processing
CVSS 5.3
CVE-2023-28152 MEDIUM
Independentsoft JWord < 1.1.110 - XML External Entity Injection via DOCX File
CVSS 5.3
CVE-2023-28685 HIGH
Jenkins AbsInt a³ Plugin <1.1.0 - XXE
CVSS 7.1
CVE-2023-27874 CRITICAL
IBM Aspera Faspex 4.4.2 - Authenticated XML External Entity Injection
CVSS 9.9
CVE-2023-26461 MEDIUM
SAP NetWeaver 7.50 - Info Disclosure
CVSS 6.8
CVE-2023-1288 MEDIUM
ENOVIA Live Collaboration >= V6R2013xE < V6R2013xE_FP.CFA.2240 - XML External Entity Injection
CVSS 6.8
CVE-2023-27476 HIGH
OWSLib < 0.28.1 - XML External Entity Injection via Unsafe XML Parser
CVSS 8.2
CVE-2023-27480 HIGH
XWiki Platform < 13.10.11 - XML External Entity Injection via XAR Import
CVSS 7.7
CVE-2023-20052 MEDIUM
ClamAV <1.0.0 - Info Disclosure
CVSS 5.3
CVE-2023-26043 MEDIUM
GeoNode < 4.0.3 - XML External Entity Injection via Style Upload
CVSS 6.5
CVE-2023-24189 CRITICAL
urule 2.1.7 - XML External Entity Injection via /urule/common/saveFile
CVSS 9.8
CVE-2023-20855 HIGH
VMware vRealize Automation and Orchestrator 8.0-8.11.0 - XML External Entity Injection
CVSS 8.8
CVE-2023-26267 MEDIUM
php-saml-sp <2.1.1 - Info Disclosure
CVSS 6.5
CVE-2023-23926 MEDIUM
APOC <5.5.0, 4.4.0.14 - XSS
CVSS 5.9
Details
Vulnerabilities 1,250