The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document place
proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling SSRF and potentially a
veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, ve
veraPDF validation provides PDF/A and PDF/UA validation, feature reporting, and metadata repair. From 1.17.35 until 1.30
Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server
In Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsin
GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Ecl
Lucee Server (or simply Lucee) is a dynamic, Java based, tag and scripting language used for rapid web application devel
NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerabil
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the C
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the S
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the l
GeoServer is an open source server that allows users to share and edit geospatial data. An improper URI validation vulne
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity
Due to the improper configuration of XML parser, user-supplied XML is parsed without applying sufficient restrictions, e
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.53.4, a LLM applicati
Improper Restriction of XML External Entity Reference vulnerability in pixelgrade Category Icon category-icon allows XML
A blind XML External Entity (XXE) injection in the OpenMessaging webservice in TecCom TecConnect 4.1 allows an unauthent
Improper restriction of XML external entity reference issue exists in DataSpider Servista 4.4 and earlier. If a speciall
IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 is vulnerable to an XML external entity injection (XXE)
Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an
XXE vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Des
The HL7 FHIR IG publisher is a tool to take a set of inputs and create a standard FHIR IG. Prior to version 1.7.4, XSLT
An XXE issue in the Director NBR component in NAKIVO Backup & Replication 10.3.x through 11.0.1 before 11.0.2 allows rem
The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) allows an unauthenticated attacker to submit an a
Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Refe
Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms al
Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to an XML External Entity
Improper Restriction of XML External Entity Reference vulnerability in Samsung Electronics MagicINFO 9 Server allows Ser
Improper Restriction of XML External Entity Reference in various Lexmark printer drivers for Windows allows attacker to
GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.
Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entit
Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network d
CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclos
The XWiki JIRA extension provides various integration points between XWiki and JIRA (macros, UI, CKEditor plugin). If th
An issue was discovered in Elspec G5 digital fault recorder version 1.2.1.12 and earlier. An XML External Entity (XXE) v
An XML External Entity (XXE) vulnerability in Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 allows att
An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie project, allowing an attacker to inject malicious
TEIGarage is a webservice and RESTful service to transform, convert and validate various formats, focussing on the TEI f
Keyoti SearchUnit prior to 9.0.0. is vulnerable to XML External Entity (XXE). An attacker who can force a vulnerable Sea
Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. A critical XML External Entit
In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker
The HTMLSectionSplitter class in langchain-text-splitters version 0.3.8 is vulnerable to XML External Entity (XXE) attac
A Server-Side Request Forgery (SSRF) vulnerability, achievable through an XML External Entity (XXE) injection, exists in
The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, valida
N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure
XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted b
KYOCERA Net Admin 3.4.0906 contains an XML External Entity (XXE) injection vulnerability in the Multi-Set Template Edito
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity
Frequently Asked Questions
What is CWE-611?
CWE-611 (CWE-611) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-611?
There are 1,556 CVE records associated with CWE-611 in our database. Of these, 259 are critical severity, 556 are high severity, and 397 are medium severity.
How can I protect against CWE-611 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-611 using AI-powered security agents.
Detect CWE-611 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-611 vulnerabilities across your infrastructure.
Get Started