CWE-611
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
1,250 vulnerabilities with CWE-611
CVE-2023-28828
MEDIUM
Polarion ALM < V22R2 - XML External Entity Injection
CVSS 5.9
CVE-2023-25955
MEDIUM
National Land Numerical Information Data Conversion Tool - XML External Entity Injection
CVSS 5.5
CVE-2023-28340
MEDIUM
Zoho ManageEngine Applications Manager <= 16320 - Authenticated XML External Entity Injection
CVSS 6.5
CVE-2023-27876
HIGH
IBM TRIRIGA 4.0 - XML External Entity Injection
CVSS 7.1
CVE-2023-20030
MEDIUM
Cisco Identity Services Engine < 3.2 - Authenticated XML External Entity Injection via XML File Upload
CVSS 6.0
CVE-2023-28684
MEDIUM
Jenkins remote-jobs-view-plugin <0.0.3 - XXE
CVSS 6.5
CVE-2023-28683
HIGH
Jenkins Phabricator Differential Plugin <2.1.5 - XXE
CVSS 8.2
CVE-2023-28682
HIGH
Jenkins Performance Publisher Plugin <8.09 - XXE
CVSS 8.2
CVE-2023-28681
HIGH
Jenkins Visual Studio Code Metrics Plugin <1.7 - XXE
CVSS 8.2
CVE-2023-28680
HIGH
Jenkins Crap4J Plugin < 0.9 - XML External Entity Injection
CVSS 7.5
CVE-2023-28150
MEDIUM
Independentsoft JODF < 1.1.110 - XML External Entity Injection via Remote DTD in DOCX File
CVSS 5.3
CVE-2023-28151
MEDIUM
Independentsoft JSpreadsheet < 1.1.110 - XML External Entity Injection via DOCX File Processing
CVSS 5.3
CVE-2023-28152
MEDIUM
Independentsoft JWord < 1.1.110 - XML External Entity Injection via DOCX File
CVSS 5.3
CVE-2023-28685
HIGH
Jenkins AbsInt a³ Plugin <1.1.0 - XXE
CVSS 7.1
CVE-2023-27874
CRITICAL
IBM Aspera Faspex 4.4.2 - Authenticated XML External Entity Injection
CVSS 9.9
CVE-2023-26461
MEDIUM
SAP NetWeaver 7.50 - Info Disclosure
CVSS 6.8
CVE-2023-1288
MEDIUM
ENOVIA Live Collaboration >= V6R2013xE < V6R2013xE_FP.CFA.2240 - XML External Entity Injection
CVSS 6.8
CVE-2023-27476
HIGH
OWSLib < 0.28.1 - XML External Entity Injection via Unsafe XML Parser
CVSS 8.2
CVE-2023-27480
HIGH
XWiki Platform < 13.10.11 - XML External Entity Injection via XAR Import
CVSS 7.7
CVE-2023-20052
MEDIUM
ClamAV <1.0.0 - Info Disclosure
CVSS 5.3
CVE-2023-26043
MEDIUM
GeoNode < 4.0.3 - XML External Entity Injection via Style Upload
CVSS 6.5
CVE-2023-24189
CRITICAL
urule 2.1.7 - XML External Entity Injection via /urule/common/saveFile
CVSS 9.8
CVE-2023-20855
HIGH
VMware vRealize Automation and Orchestrator 8.0-8.11.0 - XML External Entity Injection
CVSS 8.8
CVE-2023-26267
MEDIUM
php-saml-sp <2.1.1 - Info Disclosure
CVSS 6.5
CVE-2023-23926
MEDIUM
APOC <5.5.0, 4.4.0.14 - XSS
CVSS 5.9
Details
Vulnerabilities
1,250