Skip to content
Noroxi

CWE-611 · 1,303 records

Improper Restriction of XML External Entity Reference

CVEs in this class

1,303 records

  • XXE can expose crypt key and other secrets granting full admin access

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    adobe · commerceJun 13, 2024

  • mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    synacor · zimbra collaboration suiteMay 29, 2019

  • SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection

    CriticalCVSS 9.8KEVWeaponizedEPSS 64%

    sysaid · sysaidMay 7, 2025

  • GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature

    CriticalCVSS 9.8KEVWeaponizedEPSS 61%

    geoserver · geoserverNov 25, 2025

  • CVE-2025-2775
    73This week

    SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection

    HighCVSS 7.5KEVWeaponizedEPSS 43%

    sysaid · sysaidMay 7, 2025

  • CVE-2019-13608
    69This week

    Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.

    HighCVSS 7.5KEVWeaponizedEPSS 30%

    citrix · storefront serverAug 29, 2019

  • CVE-2022-28219
    68This week

    Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.

    CriticalCVSS 9.8WeaponizedEPSS 97%

    zohocorp · manageengine adaudit plusApr 5, 2022

  • CVE-2017-12629
    67This week

    Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config A

    CriticalCVSS 9.8Proof of conceptEPSS 92%

    apache · solrOct 14, 2017

  • CVE-2025-66516
    65This week

    Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected

    CriticalCVSS 9.8WeaponizedEPSS 88%

    apache · tikaDec 4, 2025

  • CVE-2016-9563
    63This week

    BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~t

    MediumCVSS 6.5KEVWeaponizedEPSS 24%

    sap · netweaver application server javaNov 22, 2016

  • CVE-2024-22024
    61This week

    An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and

    HighCVSS 8.3Proof of conceptEPSS 95%

    ivanti · connect secureFeb 13, 2024

  • CVE-2025-2777
    61This week

    SysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injection

    CriticalCVSS 9.8Proof of conceptEPSS 72%

    sysaid · sysaidMay 7, 2025

  • CVE-2023-45727
    61This week

    Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1

    HighCVSS 7.5KEVWeaponizedEPSS 4%

    northgrid · proselfOct 18, 2023

  • XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.

    HighCVSS 7.5Proof of conceptEPSS 92%

    ivanti · avalancheAug 13, 2024

  • D-Link D-View addDv7Probe XML External Entity Processing Information Disclosure Vulnerability

    HighCVSS 8.2No exploitEPSS 84%

    dlink · d-view 8May 2, 2024

  • Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)

    HighCVSS 8.6No exploitEPSS 77%

    adobe · experience manager formsAug 5, 2025

  • Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks.

    HighCVSS 7.5Proof of conceptEPSS 86%

    dogtagpki · dogtagpkiJul 29, 2022

  • Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or rea

    CriticalCVSS 9.1Proof of conceptEPSS 66%

    altova · mobiletogether serverAug 10, 2021

  • The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 allows remote attackers to read arbitrar

    HighCVSS 8.6Proof of conceptEPSS 69%

    adobe · coldfusionSep 1, 2016

  • WordPress Authenticated XXE attack when installation is running PHP 8

    MediumCVSS 6.5Proof of conceptEPSS 86%

    wordpress · wordpressApr 15, 2021

  • This vulnerability allows remote attackers to disclose sensitive information on affected installations of CA Arcserve D2D 16.5.

    HighCVSS 7.5No exploitEPSS 74%

    arcserve · d2dJan 20, 2021

  • When using the StreamGenerator, the code parse a user-provided XML.

    HighCVSS 7.5Proof of conceptEPSS 72%

    apache · cocoonSep 11, 2020

  • This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1.

    HighCVSS 7.5No exploitEPSS 69%

    nec · expresscluster xSep 10, 2020

  • Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows re

    CriticalCVSS 9.1Proof of conceptEPSS 50%

    zend · zend frameworkFeb 13, 2013

  • An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remot

    CriticalCVSS 9.8Proof of conceptEPSS 40%

    cyberark · enterprise password vaultMay 8, 2019

All vulnerability classes