CWE-611

Improper Restriction of XML External Entity Reference

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

1,250 vulnerabilities with CWE-611
CVE-2025-68493 HIGH
Apache Struts <6.1.0 - XML Validation
CVSS 8.1
CVE-2025-36589 HIGH
Dell Unisphere for PowerMax 9.2.4.x - XML External Entity Injection
CVSS 7.6
CVE-2025-68280 MEDIUM
Apache SIS 0.4-1.5 - XML External Entity Injection in GeoTIFF, ISO 19115, GML, and GPX Parsers
CVSS 6.5
CVE-2025-15251 MEDIUM
beecue FastBee <2.1 - XML External Entity Reference
CVSS 5.6
CVE-2025-68463 MEDIUM
Biopython < 1.86 - XML External Entity Injection in Bio.Entrez
CVSS 4.9
CVE-2025-61823 MEDIUM
ColdFusion <= 2025.4, 2023.16, 2021.22 - Authenticated XML External Entity Injection
CVSS 6.2
CVE-2025-61821 MEDIUM
Adobe ColdFusion <= 2025.4, <= 2023.16, <= 2021.22 - XML External Entity Injection
CVSS 6.8
CVE-2025-61813 HIGH
ColdFusion <= 2025.4, <= 2023.16, <= 2021.22 - XML External Entity Injection
CVSS 8.2
CVE-2025-66516 HIGH
Apache Tika 1.13-3.2.1 and tika-parsers 1.13-1.28.5 - XML External Entity Injection via Crafted XFA in PDF
CVSS 8.4
CVE-2025-65868 HIGH
eyoucms 1.7.1 - XML External Entity Injection
CVSS 7.5
CVE-2025-66372 LOW
Mustang <2.16.3 - Info Disclosure
CVSS 2.8
CVE-2025-66371 MEDIUM
Peppol-py < 1.1.1 - XML External Entity Injection via Saxon Configuration
CVSS 5.0
CVE-2025-66370 MEDIUM
kivitendo < 3.9.2 - XML External Entity Injection via ZUGFeRD Invoice Upload
CVSS 5.0
CVE-2025-58360 HIGH KEV
GeoServer WMS GetMap XXE Arbitrary File Read
CVSS 8.2
CVE-2025-63917 HIGH
PDFPatcher < 1.1.3.4663 - XML External Entity Injection via Bookmark Import
CVSS 7.1
CVE-2025-13209 MEDIUM
bestfeng oa_git_free <9.5 - XML External Entity Reference
CVSS 6.3
CVE-2025-11700 HIGH
N-able N-Central Authentication Bypass and XXE Scanner
CVSS 7.5
CVE-2025-64518 HIGH
cyclonedx-core-java 2.1.0-11.0.0 - XML External Entity Injection in Validator
CVSS 7.5
CVE-2025-63551 HIGH
MetInfo < 8.1 - Server-Side Request Forgery via XML External Entity Injection
CVSS 7.5
CVE-2025-10713 MEDIUM
WSO2 API Manager - XML External Entity Injection via Improper XML Parser Configuration
CVSS 6.5
CVE-2025-12531 HIGH
IBM InfoSphere Information Server <11.7.1.6 - XXE
CVSS 7.1
CVE-2025-64134 HIGH
Jenkins JDepend Plugin < 1.3.1 - XML External Entity Injection
CVSS 7.1
CVE-2025-46425 MEDIUM
Dell Storage Center - Dell Storage Manager <20.1.20 - XML External ...
CVSS 6.5
CVE-2025-6985 HIGH
langchain-text-splitters < 0.3.9 - XML External Entity Injection via HTMLSectionSplitter XSLT Parsing
CVSS 7.5
CVE-2025-11341 HIGH
Jinher OA < 2.0 - XML External Entity Injection via WebDesign.aspx
CVSS 7.3
Details
Vulnerabilities 1,250