IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 An XML External Entity (XXE) vulnerability in IBM InfoSphere
IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through Interim Fix 021, 7.1.0 Interim Fix 001 through Int
Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks
pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior to 0.9.2, pam_usb c
Improper Restriction of XML External Entity Reference vulnerability in Apache SIS. It is possible to write XML files
Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in PDF rendering that allows attackers to re
Tolgee is an open-source localization platform. Prior to 3.166.3, the XML parsers used for importing Android XML resourc
XML Notepad is a Windows program that provides a simple intuitive User Interface for browsing and editing XML documents.
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.12.0, an improper restrict
Oinone Pamirs 7.0.0 contains an XML External Entity (XXE) issue in its XStream-based XML parsing logic. When attacker-co
CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosu
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.2
Grav before 2.0.0-beta.2 contains an XML external entity injection vulnerability in SVG file upload processing that allo
The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, th
veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, ve
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a speci
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML External Entity Reference v
Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vul
A vulnerability was detected in Bjskzy Zhiyou ERP up to 11.0. Impacted is the function initRCForm of the file RichClient
A vulnerability was identified in O2OA up to 9.0.0. This impacts an unknown function of the file /x_program_center/jaxrs
A vulnerability was determined in opencc JFlow up to 20260129. This affects the function Imp_Done of the file src/main/j
A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote at
A vulnerability was determined in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This vulnerabi
Improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP Document Editor allows S
MSN Password Recovery 1.30 contains an XML external entity injection vulnerability that allows attackers to read local s
FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the Xerces SAX2 XMLReader constru
When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an
A vulnerability in GRASSMARLIN v3.2.1 allows crafted session data to trigger improper handling of XML input, which may
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecos
IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privile
In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and
In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE
In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers
XML External Entity (XXE) vulnerability in esaml (and its forks) allows an attacker to cause the system to read local fi
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, multiple files use simplexml_load_string()
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks. Users a
Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior contain(s) an Improper Restriction of XML External Entity Ref
A flaw has been found in thinkgem JeeSite up to 5.15.1. Impacted is an unknown function of the file /com/jeesite/common/
A vulnerability in the licensing features of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Co
Improper Restriction of XML External Entity Reference vulnerability in Apache Syncope Console. An administrator with ade
A vulnerability was detected in pkp pkp-lib up to 3.3.0-22/3.4.0-10/3.5.0-4. The affected element is the function _trans
An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. An XML External Entity (XXE) vulnerability exists i
The component accepts XML input through the publisher without disabling external entity resolution. This allows maliciou
In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, the NONET parse opti
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1
CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized disclo
Improper restriction of XML external entity reference vulnerability in ILM Informatique jOpenDocument allows Data Serial
SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.
Frequently Asked Questions
What is CWE-611?
CWE-611 (CWE-611) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-611?
There are 112 CVE records associated with CWE-611 in our database. Of these, 13 are critical severity, 40 are high severity, and 40 are medium severity.
How can I protect against CWE-611 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-611 using AI-powered security agents.
Detect CWE-611 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-611 vulnerabilities across your infrastructure.
Get Started