CWE-611

Improper Restriction of XML External Entity Reference

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

1,250 vulnerabilities with CWE-611
CVE-2026-34401 MEDIUM
XML Notepad: XML External Entity (XXE) Injection via Unsafe XmlTextReader in XML Diff and Schema Loading
CVSS 6.5
CVE-2026-29924 HIGH
Grav CMS <= 1.7.x - SVG Upload XML External Entity Injection
CVSS 7.6
CVE-2026-4980 MEDIUM
Improper Restriction of XML External Entity Reference in Inkscape
CVSS 6.3
CVE-2026-33913 HIGH
OpenEMR: XInclude Injection in CCDA Import Allows Reading Arbitrary Server Files
CVSS 7.7
CVE-2026-28809 MEDIUM
esaml SAML Library - XML External Entity File Read
CVSS 5.3
CVE-2026-33371 MEDIUM
Zimbra Collaboration 10.0-10.1 - XXE
CVSS 4.3
CVE-2026-3511 HIGH
Slovensko.Digital Autogram < 2.7.2 - Unauthenticated XML External Entity Injection via /sign Endpoint
CVSS 8.6
CVE-2026-32251 MEDIUM
Tolgee < 3.166.3 - XML External Entity Injection in Resource Import
CVSS 6.5
CVE-2026-1567 HIGH
IBM InfoSphere Information Server 11.7.0.0-11.7.1.6 - Info Disclosure
CVSS 7.1
CVE-2026-3404 MEDIUM
jeesite < 5.15.1 - XML External Entity Injection in CasOutHandler Endpoint
CVSS 5.0
CVE-2026-2252 HIGH
Xerox FreeFlow Core <=8.0.7 - XXE/SSRF
CVSS 7.5
CVE-2026-2536 MEDIUM
opencc JFlow <= 20260129 - XML External Entity Injection via File Argument in Imp_Done Function
CVSS 6.3
CVE-2026-1227 HIGH
EcoStruxure Building Operation Workstation < 7.0.3.2000 (CP1) - XXE via TGML Graphics File Upload
CVE-2026-2074 MEDIUM
O2OA <9.0.0 - SSRF
CVSS 6.3
CVE-2026-23739 LOW
Asterisk <20.7-cert9, 20.18.2, 21.12.1, 22.8.2, 23.2.2 - Info Discl...
CVSS 2.0
CVE-2026-23795 MEDIUM
Apache Syncope <3.0.15/<4.0.3 - XML External Entity Reference
CVSS 4.9
CVE-2026-21569 HIGH
Atlassian Crowd 7.1.0-7.1.2 - Authenticated XML External Entity Injection
CVSS 7.9
CVE-2026-24400 CRITICAL
assertj-core 1.4.0-3.27.6 - XML External Entity Injection in XmlStringPrettyFormatter
CVSS 9.1
CVE-2026-1218 MEDIUM
Bjskzy Zhiyou ERP <11.0 - XML External Entity Reference
CVSS 6.3
CVE-2026-22186 HIGH
Open Microscopy Environment/Bio-Formats <= 8.3.0 - XML External Entity Injection in Leica XLEF Metadata Parser
CVSS 7.1
CVE-2026-20029 MEDIUM
Cisco Identity Services Engine Software - Authenticated XML External Entity Injection via Malicious File Upload
CVSS 4.9
CVE-2025-14543 CRITICAL
RTI Connext Professional Core Libraries - XML External Entity Injection
CVSS 9.1
CVE-2025-36247 HIGH
IBM Db2 11.5.0-11.5.9/12.1.0-12.1.3 - XXE
CVSS 7.1
CVE-2025-65482 CRITICAL
opensagres XDocReport 0.9.2-2.0.3 - XML External Entity Injection via Crafted .docx File
CVSS 9.8
CVE-2025-14478 HIGH
Demo Importer Plus <2.0.9 - Authenticated RCE
CVSS 7.5
Details
Vulnerabilities 1,250