CWE-611

Improper Restriction of XML External Entity Reference

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

1,228 vulnerabilities with CWE-611
CVE-2025-54445 HIGH
Samsung Magicinfo 9 Server < 21.1080.0 - XXE
CVSS 8.2
CVE-2025-7766 HIGH
Lantronix Provisioning Manager - RCE
CVSS 8.0
CVE-2025-34142 MEDIUM
ETQ Reliance CG - XSS
CVE-2025-36603 MEDIUM
Dell Appsync < 4.6.0.4 - XXE
CVSS 4.2
CVE-2025-7824 HIGH
Jinher OA 1.1 - XML External Entity Reference
CVSS 7.3
CVE-2025-7823 HIGH
Jinher OA 1.2 - XML External Entity Reference
CVSS 7.3
CVE-2025-52162 MEDIUM
Agorum core <11.10.1 - XXE
CVSS 6.5
CVE-2025-53621 MEDIUM
DSpace <7.6.4, 8.2, 9.1 - XSS
CVSS 6.9
CVE-2025-53689 HIGH
Apache Jackrabbit <2.23.2 - Blind XXE
CVSS 8.8
CVE-2025-7523 HIGH
Jinher OA 1.0 - XML External Entity Reference
CVSS 7.3
CVE-2025-6438 MEDIUM
SOAP API - XML External Entity Injection
CVE-2025-49544 MEDIUM
Adobe Coldfusion - XXE
CVSS 6.8
CVE-2025-49539 MEDIUM
Adobe Coldfusion - XXE
CVSS 4.5
CVE-2025-49535 CRITICAL
Adobe Coldfusion - XXE
CVSS 9.3
CVE-2025-49493 MEDIUM
Akamai CloudTest <60 - XXE Injection
CVSS 5.8
CVE-2025-52888 HIGH
Io.qameta.allure.plugins Xunit-xml-plugin < 2.34.1 - XXE
CVSS 7.5
CVE-2025-47293 LOW
Com.powsybl Powsybl-commons < 6.7.2 - SSRF
CVE-2025-33121 HIGH
IBM QRadar SIEM <7.5.0-12 - XXE
CVSS 7.1
CVE-2025-36049 HIGH
IBM Webmethods Integration - XXE
CVSS 8.8
CVE-2025-44044 HIGH
Keyoti SearchUnit <9.0.0 - XXE
CVSS 7.5
CVE-2025-30220 CRITICAL
GeoServer WFS - XXE Processing Vulnerability
CVSS 9.9
CVE-2025-31039 CRITICAL
pixelgrade Category Icon <1.0.2 - SSRF
CVSS 9.1
CVE-2025-5877 MEDIUM
Fengoffice Feng Office - XXE
CVSS 6.3
CVE-2025-48882 HIGH
PHPOffice Math <0.3.0 - XSS
CVE-2025-4338 MEDIUM
Lantronix Device installer - XXE
CVSS 6.8
Details
Vulnerabilities 1,228