CWE-611
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
1,250 vulnerabilities with CWE-611
CVE-2026-34401
MEDIUM
XML Notepad: XML External Entity (XXE) Injection via Unsafe XmlTextReader in XML Diff and Schema Loading
CVSS 6.5
CVE-2026-29924
HIGH
Grav CMS <= 1.7.x - SVG Upload XML External Entity Injection
CVSS 7.6
CVE-2026-4980
MEDIUM
Improper Restriction of XML External Entity Reference in Inkscape
CVSS 6.3
CVE-2026-33913
HIGH
OpenEMR: XInclude Injection in CCDA Import Allows Reading Arbitrary Server Files
CVSS 7.7
CVE-2026-28809
MEDIUM
esaml SAML Library - XML External Entity File Read
CVSS 5.3
CVE-2026-33371
MEDIUM
Zimbra Collaboration 10.0-10.1 - XXE
CVSS 4.3
CVE-2026-3511
HIGH
Slovensko.Digital Autogram < 2.7.2 - Unauthenticated XML External Entity Injection via /sign Endpoint
CVSS 8.6
CVE-2026-32251
MEDIUM
Tolgee < 3.166.3 - XML External Entity Injection in Resource Import
CVSS 6.5
CVE-2026-1567
HIGH
IBM InfoSphere Information Server 11.7.0.0-11.7.1.6 - Info Disclosure
CVSS 7.1
CVE-2026-3404
MEDIUM
jeesite < 5.15.1 - XML External Entity Injection in CasOutHandler Endpoint
CVSS 5.0
CVE-2026-2252
HIGH
Xerox FreeFlow Core <=8.0.7 - XXE/SSRF
CVSS 7.5
CVE-2026-2536
MEDIUM
opencc JFlow <= 20260129 - XML External Entity Injection via File Argument in Imp_Done Function
CVSS 6.3
CVE-2026-1227
HIGH
EcoStruxure Building Operation Workstation < 7.0.3.2000 (CP1) - XXE via TGML Graphics File Upload
CVE-2026-2074
MEDIUM
O2OA <9.0.0 - SSRF
CVSS 6.3
CVE-2026-23739
LOW
Asterisk <20.7-cert9, 20.18.2, 21.12.1, 22.8.2, 23.2.2 - Info Discl...
CVSS 2.0
CVE-2026-23795
MEDIUM
Apache Syncope <3.0.15/<4.0.3 - XML External Entity Reference
CVSS 4.9
CVE-2026-21569
HIGH
Atlassian Crowd 7.1.0-7.1.2 - Authenticated XML External Entity Injection
CVSS 7.9
CVE-2026-24400
CRITICAL
assertj-core 1.4.0-3.27.6 - XML External Entity Injection in XmlStringPrettyFormatter
CVSS 9.1
CVE-2026-1218
MEDIUM
Bjskzy Zhiyou ERP <11.0 - XML External Entity Reference
CVSS 6.3
CVE-2026-22186
HIGH
Open Microscopy Environment/Bio-Formats <= 8.3.0 - XML External Entity Injection in Leica XLEF Metadata Parser
CVSS 7.1
CVE-2026-20029
MEDIUM
Cisco Identity Services Engine Software - Authenticated XML External Entity Injection via Malicious File Upload
CVSS 4.9
CVE-2025-14543
CRITICAL
RTI Connext Professional Core Libraries - XML External Entity Injection
CVSS 9.1
CVE-2025-36247
HIGH
IBM Db2 11.5.0-11.5.9/12.1.0-12.1.3 - XXE
CVSS 7.1
CVE-2025-65482
CRITICAL
opensagres XDocReport 0.9.2-2.0.3 - XML External Entity Injection via Crafted .docx File
CVSS 9.8
CVE-2025-14478
HIGH
Demo Importer Plus <2.0.9 - Authenticated RCE
CVSS 7.5
Details
Vulnerabilities
1,250