CWE-611

Improper Restriction of XML External Entity Reference

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

1,250 vulnerabilities with CWE-611
CVE-2025-2777 CRITICAL
SysAid On-Prem <= 23.3.40 - XML External Entity
CVSS 9.3
CVE-2025-2776 CRITICAL KEV
SysAid On-Prem <= 23.3.40 - XML External Entity
CVSS 9.3
CVE-2025-2775 CRITICAL KEV
SysAid On-Prem <= 23.3.40 - XML External Entity
CVSS 9.3
CVE-2025-22478 HIGH
Dell Storage Manager 20.1.20 - Unauthenticated XML External Entity Injection
CVSS 8.1
CVE-2025-46726 CRITICAL
langroid < 0.53.4 - XML External Entity Injection via XMLToolMessage
CVSS 9.1
CVE-2025-2905 CRITICAL
WSO2 API Manager < 2.0.0 and am-distribution-parent < 2.1.0 - XML External Entity Injection
CVSS 9.1
CVE-2025-34490 MEDIUM
GFI MailEssentials < 21.8 - Authenticated XML External Entity Injection
CVSS 6.5
CVE-2025-2070 MEDIUM
FileZ Client < 11.0.0.10 - XML External Entity Injection via Crafted URL
CVSS 5.0
CVE-2025-24911 MEDIUM
Hitachi Vantara Pentaho Business Analytics Server <9.3.* & 10.0-10.2.0.2 - XXE in Data Access XMLParserFactoryProducer
CVSS 4.9
CVE-2025-24910 MEDIUM
Hitachi Vantara Pentaho Business Analytics Server <9.3.* & 10.0-10.2.0.2 - XXE Injection
CVSS 4.9
CVE-2025-31497 HIGH
TEIGarage < 1.2.4 - XML External Entity Injection in Document Conversion Service
CVSS 7.5
CVE-2025-32406 HIGH
NAKIVO Backup & Replication <11.0.2 - XSS
CVSS 8.6
CVE-2025-32138 MEDIUM
Supsystic Easy Google Maps <1.11.17 - XML Injection
CVSS 6.6
CVE-2025-3241 MEDIUM
zhangyanbo2007 youkefu <4.2.0 - SSRF
CVSS 6.3
CVE-2025-31487 HIGH
XWiki JIRA Extension 4.2-8.5.6 - Authenticated XML External Entity Injection via JIRA Macro
CVSS 7.7
CVE-2025-1781 MEDIUM
W3CSS Validator <cssval-20250226 - SSRF
CVSS 6.5
CVE-2025-29932 MEDIUM
JetBrains GoLand < 2025.1 - XML External Entity Injection during Debugging
CVSS 4.1
CVE-2025-25036 MEDIUM
Jalios JPlatform <10.0.8 - XML Injection
CVSS 6.8
CVE-2025-2365 MEDIUM
crmeb_java <= 1.3.4 - XML External Entity Injection in WeChatMessageController
CVSS 6.3
CVE-2025-27136 MEDIUM
LocalS3 < 1.21 - XML External Entity Injection via Bucket Creation Endpoint
CVE-2025-0162 HIGH
IBM Aspera Shares <1.10.0 PL7 - XXE
CVSS 7.1
CVE-2025-24521 MEDIUM
XML Entity Injection - Info Disclosure
CVSS 4.9
CVE-2025-1225 MEDIUM
ywoa <2024.07.03 - XML External Entity Reference
CVSS 6.3
CVE-2025-23195 HIGH
Apache Ambari < 2.7.9 - XML External Entity Injection via DocumentBuilderFactory
CVSS 7.5
CVE-2024-13971 HIGH
Arbitrary File Read and Server Side Request Forgery via XML External Entities in Lobster_pro
CVSS 7.5
Details
Vulnerabilities 1,250