CWE-611

Improper Restriction of XML External Entity Reference

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

1,228 vulnerabilities with CWE-611
CVE-2026-22186 HIGH
OME Pom-bio-formats - XXE
CVSS 7.1
CVE-2026-20029 MEDIUM
Cisco ISE - Info Disclosure
CVSS 4.9
CVE-2025-14543 HIGH
Improper Restriction of XML External Entity Reference vulnerability in Connext Professional (Core Libraries) allows Serialized Data External Linking.
CVE-2025-36247 HIGH
IBM Db2 11.5.0-11.5.9/12.1.0-12.1.3 - XXE
CVSS 7.1
CVE-2025-65482 CRITICAL
Opensagres Xdocreport < 2.0.3 - XXE
CVSS 9.8
CVE-2025-14478 HIGH
Demo Importer Plus <2.0.9 - Authenticated RCE
CVSS 7.5
CVE-2025-68493 HIGH
Apache Struts <6.1.0 - XML Validation
CVSS 8.1
CVE-2025-36589 HIGH
Dell Unisphere For Powermax < 9.2.4.19 - XXE
CVSS 7.6
CVE-2025-68280 MEDIUM
Apache Spatial Information System < 1.5 - XXE
CVSS 6.5
CVE-2025-15251 MEDIUM
beecue FastBee <2.1 - XML External Entity Reference
CVSS 5.6
CVE-2025-68463 MEDIUM
Pypi Biopython - XXE
CVSS 4.9
CVE-2025-61823 MEDIUM
Adobe Coldfusion - XXE
CVSS 6.2
CVE-2025-61821 MEDIUM
Adobe Coldfusion - XXE
CVSS 6.8
CVE-2025-61813 HIGH
Adobe Coldfusion - XXE
CVSS 8.2
CVE-2025-66516 HIGH
Apache Tika <3.2.1 - XXE
CVSS 8.4
CVE-2025-65868 HIGH
eyoucms <1.7.1 - DoS
CVSS 7.5
CVE-2025-66372 LOW
Mustang <2.16.3 - Info Disclosure
CVSS 2.8
CVE-2025-66371 MEDIUM
Peppol-py <1.1.1 - XSS
CVSS 5.0
CVE-2025-66370 MEDIUM
Kivitendo <3.9.2 - Info Disclosure
CVSS 5.0
CVE-2025-58360 HIGH KEV
GeoServer WMS GetMap XXE Arbitrary File Read
CVSS 8.2
CVE-2025-63917 HIGH
PDFPatcher <1.1.3.4663 - XXE
CVSS 7.1
CVE-2025-13209 MEDIUM
bestfeng oa_git_free <9.5 - XML External Entity Reference
CVSS 6.3
CVE-2025-11700 HIGH
N-able N-Central Authentication Bypass and XXE Scanner
CVSS 7.5
CVE-2025-64518 HIGH
Org.cyclonedx Cyclonedx-core-java < 11.0.1 - XXE
CVSS 7.5
CVE-2025-63551 HIGH
MetInfo CMS <8.1 - SSRF
CVSS 7.5
Details
Vulnerabilities 1,228