CWE-611
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
1,250 vulnerabilities with CWE-611
CVE-2025-68493
HIGH
Apache Struts <6.1.0 - XML Validation
CVSS 8.1
CVE-2025-36589
HIGH
Dell Unisphere for PowerMax 9.2.4.x - XML External Entity Injection
CVSS 7.6
CVE-2025-68280
MEDIUM
Apache SIS 0.4-1.5 - XML External Entity Injection in GeoTIFF, ISO 19115, GML, and GPX Parsers
CVSS 6.5
CVE-2025-15251
MEDIUM
beecue FastBee <2.1 - XML External Entity Reference
CVSS 5.6
CVE-2025-68463
MEDIUM
Biopython < 1.86 - XML External Entity Injection in Bio.Entrez
CVSS 4.9
CVE-2025-61823
MEDIUM
ColdFusion <= 2025.4, 2023.16, 2021.22 - Authenticated XML External Entity Injection
CVSS 6.2
CVE-2025-61821
MEDIUM
Adobe ColdFusion <= 2025.4, <= 2023.16, <= 2021.22 - XML External Entity Injection
CVSS 6.8
CVE-2025-61813
HIGH
ColdFusion <= 2025.4, <= 2023.16, <= 2021.22 - XML External Entity Injection
CVSS 8.2
CVE-2025-66516
HIGH
Apache Tika 1.13-3.2.1 and tika-parsers 1.13-1.28.5 - XML External Entity Injection via Crafted XFA in PDF
CVSS 8.4
CVE-2025-65868
HIGH
eyoucms 1.7.1 - XML External Entity Injection
CVSS 7.5
CVE-2025-66372
LOW
Mustang <2.16.3 - Info Disclosure
CVSS 2.8
CVE-2025-66371
MEDIUM
Peppol-py < 1.1.1 - XML External Entity Injection via Saxon Configuration
CVSS 5.0
CVE-2025-66370
MEDIUM
kivitendo < 3.9.2 - XML External Entity Injection via ZUGFeRD Invoice Upload
CVSS 5.0
CVE-2025-58360
HIGH
KEV
GeoServer WMS GetMap XXE Arbitrary File Read
CVSS 8.2
CVE-2025-63917
HIGH
PDFPatcher < 1.1.3.4663 - XML External Entity Injection via Bookmark Import
CVSS 7.1
CVE-2025-13209
MEDIUM
bestfeng oa_git_free <9.5 - XML External Entity Reference
CVSS 6.3
CVE-2025-11700
HIGH
N-able N-Central Authentication Bypass and XXE Scanner
CVSS 7.5
CVE-2025-64518
HIGH
cyclonedx-core-java 2.1.0-11.0.0 - XML External Entity Injection in Validator
CVSS 7.5
CVE-2025-63551
HIGH
MetInfo < 8.1 - Server-Side Request Forgery via XML External Entity Injection
CVSS 7.5
CVE-2025-10713
MEDIUM
WSO2 API Manager - XML External Entity Injection via Improper XML Parser Configuration
CVSS 6.5
CVE-2025-12531
HIGH
IBM InfoSphere Information Server <11.7.1.6 - XXE
CVSS 7.1
CVE-2025-64134
HIGH
Jenkins JDepend Plugin < 1.3.1 - XML External Entity Injection
CVSS 7.1
CVE-2025-46425
MEDIUM
Dell Storage Center - Dell Storage Manager <20.1.20 - XML External ...
CVSS 6.5
CVE-2025-6985
HIGH
langchain-text-splitters < 0.3.9 - XML External Entity Injection via HTMLSectionSplitter XSLT Parsing
CVSS 7.5
CVE-2025-11341
HIGH
Jinher OA < 2.0 - XML External Entity Injection via WebDesign.aspx
CVSS 7.3
Details
Vulnerabilities
1,250