CWE-611
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
1,228 vulnerabilities with CWE-611
CVE-2025-27136
MEDIUM
LocalS3 <1.21 - XXE Injection
CVE-2025-0162
HIGH
IBM Aspera Shares <1.10.0 PL7 - XXE
CVSS 7.1
CVE-2025-24521
MEDIUM
XML Entity Injection - Info Disclosure
CVSS 4.9
CVE-2025-1225
MEDIUM
ywoa <2024.07.03 - XML External Entity Reference
CVSS 6.3
CVE-2025-23195
HIGH
Apache Ambari < 2.7.9 - XXE
CVSS 7.5
CVE-2024-13971
HIGH
Arbitrary File Read and Server Side Request Forgery via XML External Entities in Lobster_pro
CVE-2024-39847
HIGH
Arbitrary File Read and Server Side Request Forgery via XML External Entities in 4D Server SOAP
CVE-2024-8010
LOW
XML External Entity Injection via Publisher in WSO2 API Manager Allows Reading Arbitrary Files
CVSS 3.5
CVE-2024-2374
HIGH
XML External Entity Injection in Multiple WSO2 Products Allows Arbitrary file read and Denial of Service
CVSS 7.5
CVE-2024-58335
MEDIUM
OpenXRechnungToolbox <6c50e89 - XML External Entity
CVSS 5.0
CVE-2024-34711
CRITICAL
Osgeo Geoserver < 2.25.0 - Information Disclosure
CVSS 9.3
CVE-2024-51445
MEDIUM
Siemens Polarion Alm < 2404.4 - XXE
CVSS 6.5
CVE-2024-49781
HIGH
IBM OpenPages <9.0 - XXE
CVSS 7.1
CVE-2024-25066
MEDIUM
RSA Authentication Manager <8.7 SP2 - XSS
CVSS 4.3
CVE-2024-54171
HIGH
IBM EntireX 11.1 - XXE
CVSS 7.1
CVE-2024-49352
HIGH
IBM Cognos Analytics < 11.2.4 - XXE
CVSS 7.1
CVE-2024-52807
HIGH
Org.hl7.fhir.publisher.cli < 1.7.4 - XXE
CVSS 8.6
CVE-2024-42185
LOW
BigFix Patch Download Plug-ins - Code Injection
CVSS 2.5
CVE-2024-12476
HIGH
Web Designer <unknown - Info Disclosure/Remote Code Execution
CVSS 7.8
CVE-2024-12298
MEDIUM
NB-series NX-Designer - Info Disclosure
CVSS 5.5
CVE-2024-46603
HIGH
Elspec-ltd G5dfr Firmware < 1.2.2.19 - XXE
CVSS 7.5
CVE-2024-46602
HIGH
Elspec-ltd G5dfr Firmware < 1.2.2.19 - XXE
CVSS 7.5
CVE-2024-56324
HIGH
Thoughtworks Gocd < 24.5.0 - XXE
CVSS 7.1
CVE-2024-56322
HIGH
Thoughtworks Gocd < 24.5.0 - XXE
CVSS 7.2
CVE-2024-40896
CRITICAL
libxml2 <2.11.9-2.13.3 - XSS
CVSS 9.1
Details
Vulnerabilities
1,228