VulnSea

CWE-611

CVEs classified under CWE-611, newest first.

78 CVEsRSS

CVE-2026-71375High· 7.4
2w ago

Improper restriction of XML external entity reference vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-5…

Improper restriction of XML external entity reference vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-5…

▾ TwilightHitachi · Cosminexus Component ContainerEPSS 0.41%via NVD
CVE-2026-76958High· 8.5
2w ago

SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components

SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML payloads containing malicious external …

▾ TwilightSAP_SE · SAP Integration SuiteEPSS 0.38%via NVD
CVE-2026-17444Medium· 5.3
3w ago

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML ex…

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML ex…

▾ Sunlitibm · app_connect_enterpriseEPSS 0.29%via NVD
CVE-2026-17443Medium· 5.3
3w ago

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML ex…

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML ex…

▾ Sunlitibm · app_connect_enterpriseEPSS 0.29%via NVD
CVE-2026-81832High· 7.7
3w ago

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 SAP Adapter is vulnerable to an XML external entity (XXE) attack.

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 SAP Adapter is vulnerable to an XML external entity (XXE) attack.

▾ Twilightibm · app_connect_enterpriseEPSS 0.38%via NVD
CVE-2026-82918Medium· 5.5
3w ago

XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporation improperly restrict XML external entity references

XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporation improperly restrict XML external entity references. If a user opens a specially crafted setting file, the sensitive information stored in the system where XG Visio…

▾ SunlitKeyence Corporation · XG-X VisionTerminalEPSS 0.18%via NVD
CVE-2026-82525Medium· 5.5
3w ago

Exterro FTK Imager before 8.3 contains an XML external entity (XXE) injection vulnerability that allows attackers to read arbitrary files from the host filesystem by embedding malicious external entity references and attacker-controlled …

Exterro FTK Imager before 8.3 contains an XML external entity (XXE) injection vulnerability that allows attackers to read arbitrary files from the host filesystem by embedding malicious external entity references and attacker-controlled …

▾ SunlitExterro · FTK ImagerEPSS 0.20%via NVD
CVE-2026-17615High· 7.5
3w ago

A flaw was found in RESTEasy's SourceProvider

A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external …

▾ TwilightRed Hat · keycloak-rhel9-containerEPSS 0.35%via NVD
CVE-2026-55848High· 8.6
1mo ago

mapfish-print is a component of MapFish for printing templated cartographic maps

mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.33.16, and 4.0.5, MapFish Print accepts an attacker-controlled GML layer url in requests to the /api/print3/print end…

▾ Twilightmapfish · org.mapfish.print:print-libEPSS 0.53%via NVD
CVE-2026-75055Medium· 5.5
1mo ago

In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE

In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE

▾ Sunlitjetbrains · intellij_ideaEPSS 0.15%via NVD
CVE-2026-75058Medium· 5.5
1mo ago

In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers

In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers

▾ Sunlitjetbrains · intellij_ideaEPSS 0.15%via NVD
CVE-2026-69101High· 7.7PoC
1mo ago

Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to perform server-side request forgery and out-of-band file exfiltration by supplying a crafted taskScript payload to t…

Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to perform server-side request forgery and out-of-band file exfiltration by supplying a crafted taskScript payload to t…

▾ Midnightdatavane · tisEPSS 0.43%via NVD
CVE-2026-73235Medium· 6.1
1mo ago

FreeCAD is a free and open-source multiplatform 3D parametric modeler

FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the Xerces SAX2 XMLReader constructed in src/Base/Reader.cpp by Base::XMLReader::XMLReader() parses attacker-controlled Document.xml from a crafted .F…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-54079High
2mo ago

veraPDF Validation XXE via XFA

veraPDF Validation XXE via XFA

▾ Twilightverapdf · org.verapdf:validation-modelEPSS 0.56%via GHSA
CVE-2026-54078High
2mo ago

veraPDF Validation XXE via Rich Text

veraPDF Validation XXE via Rich Text

▾ Twilightverapdf · org.verapdf:validation-modelEPSS 0.56%via GHSA
CVE-2026-54082Medium· 6.5
2mo ago

veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs

veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs

▾ Sunlitverapdf · org.verapdf:validation-modelEPSS 0.40%via GHSA
CVE-2026-56817High· 7.5
2mo ago

io.netty/netty-codec-xml: Netty: Information disclosure via XML External Entity (XXE) vulnerability (CVE-2026-56817)

A flaw was found in Netty, a network application framework. A remote attacker could exploit this vulnerability by sending specially crafted XML data containing a DOCTYPE declaration to a vulnerable XmlDecoder within the Netty channel pipel…

▾ TwilightRed Hat · Red Hat JBoss Enterprise Application Platform 7EPSS 0.69%via CSAF
CVE-2026-48359Critical· 9.6
2mo ago

Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could expl…

▾ Midnightadobe · experience_managerEPSS 1.0%via NVD
CVE-2026-54470Medium· 5.3
2mo ago

Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior contain(s) an Improper Restriction of XML External Entity Reference vulnerability

Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, lead…

▾ Sunlitdell · unisphere_for_powermaxEPSS 0.30%via NVD
CVE-2026-54640High· 7.6
2mo ago

OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAssetImport() allows arbitrary file read via unprotected XMLInputFactory

OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAssetImport() allows arbitrary file read via unprotected XMLInputFactory

▾ Twilightopenremote · io.openremote:openremote-agentvia GHSA
CVE-2026-47898None
2mo ago

Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Apache Lucene.Net.Analysis.Common: from 4.8.0-beta00005 before 4.8.0-beta00018. Users are…

Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Apache Lucene.Net.Analysis.Common: from 4.8.0-beta00005 before 4.8.0-beta00018. Users are…

▾ SunlitEPSS 0.47%via NVD
CVE-2026-12975High· 8.5
3mo ago

A flaw was found in Apicurio Registry

A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParserFactory without enabling secure processing features or disabling external entity resolution. An attacker with artifact-write permission …

▾ Twilightredhat · build_of_apicurio_registryEPSS 0.44%via NVD
GHSA-32fw-h446-j4hhHigh· 6.5
3mo ago

Duplicate Advisory: Grav is Vulnerable to XXE via SVG Upload

Duplicate Advisory: Grav is Vulnerable to XXE via SVG Upload

▾ Twilightgetgrav · getgrav/gravvia GHSA
GHSA-8678-w3jw-xfc2Low· 2.6
3mo ago

Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247

Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247

▾ Sunlitnokogiri · nokogirivia GHSA
CVE-2026-55471Critical
3mo ago

HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory

HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory

▾ Midnightuhn · ca.uhn.hapi.fhir:org.hl7.fhir.utilitiesEPSS 0.57%via GHSA
CVE-2026-49875Critical· 9.8⚖ disputed
3mo ago

Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgr…

Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgr…

▾ Midnightapache · cxfEPSS 0.81%via NVD
CVE-2025-58175Medium· 6.5
3mo ago

GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution

GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution

▾ Sunlitgeoserver · org.geoserver.web:gs-web-appEPSS 0.47%via GHSA
CVE-2026-40998High· 8.2
3mo ago

Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK's default DocumentBuilderFactory behavior instead of Spring's hardened parser config…

Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK's default DocumentBuilderFactory behavior instead of Spring's hardened parser config…

▾ Twilightbroadcom · spring_web_servicesEPSS 0.39%via NVD
CVE-2026-40991Medium· 5.9
3mo ago

When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an attacker who compromises the API or tricks the user into documenting a malicious API can perform an XXE injection att…

When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an attacker who compromises the API or tricks the user into documenting a malicious API can perform an XXE injection att…

▾ Sunlitbroadcom · spring_rest_docsEPSS 0.29%via NVD
CVE-2026-56701Medium· 6.5
4mo ago

Grav is Vulnerable to XXE via SVG Upload

Grav is Vulnerable to XXE via SVG Upload

▾ Sunlitgetgrav · getgrav/gravEPSS 0.40%via GHSA
CWE-611 vulnerabilities (CVEs) — page 2 · VulnSea