CWE-611
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
1,252 vulnerabilities with CWE-611
CVE-2021-22498
HIGH
Micro Focus Application Lifecycle Management 12.x-12.60 Patch 5, 15.0.1 Patch 2, 15.5 - XML External Entity Injection
CVSS 8.1
CVE-2021-23899
CRITICAL
OWASP json-sanitizer < 1.2.2 - HTML and XML Injection via Crafted Input
CVSS 9.8
CVE-2021-21470
MEDIUM
SAP EPM Add-in 1010 & SAP Analysis Office 2.8 - Authenticated XXE in Logging Service
CVSS 4.4
CVE-2020-37192
MEDIUM
MSN Password Recovery 1.30 - Info Disclosure
CVSS 6.2
CVE-2020-26066
MEDIUM
Cisco SD-WAN vManage - Authenticated XML External Entity Injection via Crafted XML File Import
CVSS 6.5
CVE-2020-26064
HIGH
Cisco SD-WAN vManage Software - Authenticated XML External Entity Injection via XML File Import
CVSS 8.1
CVE-2020-26710
HIGH
easy-parse 0.1.1 - XML External Entity Injection via Crafted XML File
CVSS 7.5
CVE-2020-26709
HIGH
py-xml 1.0 - XML External Entity Injection via Crafted XML File
CVSS 7.5
CVE-2020-26708
HIGH
requests-xml 0.2.3 - XML External Entity Injection
CVSS 7.5
CVE-2020-36641
MEDIUM
gturri aXMLRPC <1.14.0 - XML External Entity Reference
CVSS 5.5
CVE-2020-36640
MEDIUM
bonitasoft bonita-connector-webservice <1.3.0 - SSRF
CVSS 5.5
CVE-2020-14379
MEDIUM
Redhat Jboss A-mq - XXE
CVSS 5.6
CVE-2020-21641
HIGH
Zoho ManageEngine Analytics Plus < 4.3.5 - XML External Entity Injection via Crafted License File
CVSS 7.5
CVE-2020-14478
HIGH
FactoryTalk Services Platform < 6.11.00 - Authenticated XML External Entity Injection
CVSS 7.1
CVE-2020-4876
HIGH
IBM Cognos Controller 10.4.0-10.4.2 - XML External Entity Injection
CVSS 8.2
CVE-2020-4875
HIGH
IBM Cognos Controller 10.4.0-10.4.2 - XML External Entity Injection
CVSS 8.2
CVE-2020-26705
CRITICAL
Easy-XML 0.5.0 - XML External Entity Disclosure or Denial of Service
CVSS 9.1
CVE-2020-25912
CRITICAL
Symphony CMS 2.7.10 - XML External Entity Disclosure or Denial of Service
CVSS 9.1
CVE-2020-25911
CRITICAL
MODX Revolution < 2.8.0 - XML External Entity Injection in modRestServiceRequest
CVSS 9.1
CVE-2020-19954
HIGH
S-CMS 3.0 - XML External Entity Arbitrary File Read
CVSS 7.5
CVE-2020-18705
CRITICAL
Quokka v0.4.0 - XML External Entity Injection in Content Views
CVSS 9.8
CVE-2020-18703
CRITICAL
Quokka v0.4.0 - XML External Entity Injection in quokka/utils/atom.py
CVSS 9.8
CVE-2020-26564
MEDIUM
ObjectPlanet Opinio <7.15 - XML External Entity
CVSS 6.5
CVE-2020-5323
MEDIUM
Dell EMC OpenManage Enterprise < 3.2 & OpenManage Enterprise-Modular < 1.10.00 - XXE Injection
CVSS 5.4
CVE-2020-5003
CRITICAL
IBM Financial Transaction Manager 3.2.4 - XML External Entity Injection
CVSS 9.1
Details
Vulnerabilities
1,252