CWE-611 · 1,303 records
Improper Restriction of XML External Entity Reference
CVEs in this class
1,303 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2024-34102Weaponized | XXE can expose crypt key and other secrets granting full admin accessadobe · commerce · CWE-611 | Critical9.8 | KEV | 100.0% | Jun 13, 2024 |
99Now | CVE-2019-9670Weaponized | mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, assynacor · zimbra collaboration suite · CWE-611 | Critical9.8 | KEV | 100.0% | May 29, 2019 |
88Now | CVE-2025-2776Weaponized | SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injectionsysaid · sysaid · CWE-611 | Critical9.8 | KEV | 64.4% | May 7, 2025 |
87Now | CVE-2025-58360Weaponized | GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap featuregeoserver · geoserver · CWE-611 | Critical9.8 | KEV | 60.5% | Nov 25, 2025 |
73This week | CVE-2025-2775Weaponized | SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injectionsysaid · sysaid · CWE-611 | High7.5 | KEV | 43.0% | May 7, 2025 |
69This week | CVE-2019-13608Weaponized | Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.citrix · storefront server · CWE-611 | High7.5 | KEV | 30.0% | Aug 29, 2019 |
68This week | CVE-2022-28219Weaponized | Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.zohocorp · manageengine adaudit plus · CWE-611 | Critical9.8 | — | 97.2% | Apr 5, 2022 |
67This week | CVE-2017-12629Proof of concept | Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config Aapache · solr · CWE-611 | Critical9.8 | — | 91.9% | Oct 14, 2017 |
65This week | CVE-2025-66516Weaponized | Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affectedapache · tika · CWE-611 | Critical9.8 | — | 88.1% | Dec 4, 2025 |
63This week | CVE-2016-9563Weaponized | BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tsap · netweaver application server java · CWE-611 | Medium6.5 | KEV | 24.2% | Nov 22, 2016 |
61This week | CVE-2024-22024Proof of concept | An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) andivanti · connect secure · CWE-611 | High8.3 | — | 94.7% | Feb 13, 2024 |
61This week | CVE-2025-2777Proof of concept | SysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injectionsysaid · sysaid · CWE-611 | Critical9.8 | — | 72.2% | May 7, 2025 |
61This week | CVE-2023-45727Weaponized | Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1northgrid · proself · CWE-611 | High7.5 | KEV | 3.5% | Oct 18, 2023 |
58Plan | CVE-2024-38653Proof of concept | XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.ivanti · avalanche · CWE-611 | High7.5 | — | 92.0% | Aug 13, 2024 |
57Plan | CVE-2023-44412No exploit | D-Link D-View addDv7Probe XML External Entity Processing Information Disclosure Vulnerabilitydlink · d-view 8 · CWE-611 | High8.2 | — | 83.7% | May 2, 2024 |
57Plan | CVE-2025-54254No exploit | Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)adobe · experience manager forms · CWE-611 | High8.6 | — | 77.5% | Aug 5, 2025 |
56Plan | CVE-2022-2414Proof of concept | Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks.dogtagpki · dogtagpki · CWE-611 | High7.5 | — | 86.0% | Jul 29, 2022 |
56Plan | CVE-2021-37425Proof of concept | Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reaaltova · mobiletogether server · CWE-611 | Critical9.1 | — | 66.3% | Aug 10, 2021 |
55Plan | CVE-2016-4264Proof of concept | The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 allows remote attackers to read arbitraradobe · coldfusion · CWE-611 | High8.6 | — | 69.0% | Sep 1, 2016 |
52Plan | CVE-2021-29447Proof of concept | WordPress Authenticated XXE attack when installation is running PHP 8wordpress · wordpress · CWE-611 | Medium6.5 | — | 85.7% | Apr 15, 2021 |
52Plan | CVE-2020-27858No exploit | This vulnerability allows remote attackers to disclose sensitive information on affected installations of CA Arcserve D2D 16.5.arcserve · d2d · CWE-611 | High7.5 | — | 73.8% | Jan 20, 2021 |
52Plan | CVE-2020-11991Proof of concept | When using the StreamGenerator, the code parse a user-provided XML.apache · cocoon · CWE-611 | High7.5 | — | 72.5% | Sep 11, 2020 |
51Plan | CVE-2020-17408No exploit | This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1.nec · expresscluster x · CWE-611 | High7.5 | — | 69.3% | Sep 10, 2020 |
51Plan | CVE-2012-3363Proof of concept | Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows rezend · zend framework · CWE-611 | Critical9.1 | — | 50.2% | Feb 13, 2013 |
51Plan | CVE-2019-7442Proof of concept | An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remotcyberark · enterprise password vault · CWE-611 | Critical9.8 | — | 40.0% | May 8, 2019 |
- CVE-2024-3410299Now
XXE can expose crypt key and other secrets granting full admin access
CriticalCVSS 9.8KEVWeaponizedEPSS 100%adobe · commerceJun 13, 2024
- CVE-2019-967099Now
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as
CriticalCVSS 9.8KEVWeaponizedEPSS 100%synacor · zimbra collaboration suiteMay 29, 2019
- CVE-2025-277688Now
SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection
CriticalCVSS 9.8KEVWeaponizedEPSS 64%sysaid · sysaidMay 7, 2025
- CVE-2025-5836087Now
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
CriticalCVSS 9.8KEVWeaponizedEPSS 61%geoserver · geoserverNov 25, 2025
- CVE-2025-277573This week
SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection
HighCVSS 7.5KEVWeaponizedEPSS 43%sysaid · sysaidMay 7, 2025
- CVE-2019-1360869This week
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.
HighCVSS 7.5KEVWeaponizedEPSS 30%citrix · storefront serverAug 29, 2019
- CVE-2022-2821968This week
Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.
CriticalCVSS 9.8WeaponizedEPSS 97%zohocorp · manageengine adaudit plusApr 5, 2022
- CVE-2017-1262967This week
Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config A
CriticalCVSS 9.8Proof of conceptEPSS 92%apache · solrOct 14, 2017
- CVE-2025-6651665This week
Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected
CriticalCVSS 9.8WeaponizedEPSS 88%apache · tikaDec 4, 2025
- CVE-2016-956363This week
BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~t
MediumCVSS 6.5KEVWeaponizedEPSS 24%sap · netweaver application server javaNov 22, 2016
- CVE-2024-2202461This week
An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and
HighCVSS 8.3Proof of conceptEPSS 95%ivanti · connect secureFeb 13, 2024
- CVE-2025-277761This week
SysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injection
CriticalCVSS 9.8Proof of conceptEPSS 72%sysaid · sysaidMay 7, 2025
- CVE-2023-4572761This week
Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1
HighCVSS 7.5KEVWeaponizedEPSS 4%northgrid · proselfOct 18, 2023
- CVE-2024-3865358Plan
XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.
HighCVSS 7.5Proof of conceptEPSS 92%ivanti · avalancheAug 13, 2024
- CVE-2023-4441257Plan
D-Link D-View addDv7Probe XML External Entity Processing Information Disclosure Vulnerability
HighCVSS 8.2No exploitEPSS 84%dlink · d-view 8May 2, 2024
- CVE-2025-5425457Plan
Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
HighCVSS 8.6No exploitEPSS 77%adobe · experience manager formsAug 5, 2025
- CVE-2022-241456Plan
Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks.
HighCVSS 7.5Proof of conceptEPSS 86%dogtagpki · dogtagpkiJul 29, 2022
- CVE-2021-3742556Plan
Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or rea
CriticalCVSS 9.1Proof of conceptEPSS 66%altova · mobiletogether serverAug 10, 2021
- CVE-2016-426455Plan
The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 allows remote attackers to read arbitrar
HighCVSS 8.6Proof of conceptEPSS 69%adobe · coldfusionSep 1, 2016
- CVE-2021-2944752Plan
WordPress Authenticated XXE attack when installation is running PHP 8
MediumCVSS 6.5Proof of conceptEPSS 86%wordpress · wordpressApr 15, 2021
- CVE-2020-2785852Plan
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CA Arcserve D2D 16.5.
HighCVSS 7.5No exploitEPSS 74%arcserve · d2dJan 20, 2021
- CVE-2020-1199152Plan
When using the StreamGenerator, the code parse a user-provided XML.
HighCVSS 7.5Proof of conceptEPSS 72%apache · cocoonSep 11, 2020
- CVE-2020-1740851Plan
This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1.
HighCVSS 7.5No exploitEPSS 69%nec · expresscluster xSep 10, 2020
- CVE-2012-336351Plan
Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows re
CriticalCVSS 9.1Proof of conceptEPSS 50%zend · zend frameworkFeb 13, 2013
- CVE-2019-744251Plan
An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remot
CriticalCVSS 9.8Proof of conceptEPSS 40%cyberark · enterprise password vaultMay 8, 2019