External XML entity injection allows arbitrary download of files. The score without least privilege principle violation
Overview XML documents optionally contain a Document Type Definition (DTD), which, among other features, enable
Overview XML documents optionally contain a Document Type Definition (DTD), which, among other features, enable
Bio.Entrez in Biopython through 186 allows doctype XXE.
In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity
RSA Authentication Manager before 8.7 SP2 Patch 1 allows XML External Entity (XXE) attacks via a license file, resulting
Dell AppSync, version(s) 4.6.0.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low
In JetBrains GoLand before 2025.1 an XXE during debugging was possible
Agiloft Release 28 contains an XML External Entities vulnerability in any table that allows 'import/export', allowing an
Mustang before 2.16.3 allows exfiltrating files via XXE attacks.
BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML injection attacks. This
LocalS3 is an Amazon S3 mock service for testing and local development. Prior to version 1.21, the LocalS3 service's buc
Sulu is an open-source PHP content management system based on the Symfony framework. Starting in versions 2.5.21, 2.6.5,
CWE-611 Improper Restriction of XML External Entity Reference in the getDocumentBuilder() method of WebDav servlet in Pe
Improper Restriction of XML External Entity Reference vulnerability in bonigarcia webdrivermanager WebDriverManager on W
PHPOffice Math is a library that provides a set of classes to manipulate different formula file formats. Prior to versio
PowSyBl (Power System Blocks) is a framework to build power system oriented software. Prior to version 6.7.2, in certain
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause manipulati
An XML External Entity (XXE) injection vulnerability exists in ETQ Reliance on the CG (legacy) platform within the `/res
OpenKilda is an open-source OpenFlow controller. Prior to version 1.164.0, an XML external entity (XXE) injection vulner
Sangfor Behavior Management System (also referred to as DC Management System in Chinese-language documentation) contains
An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code and cause a denial of s
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML E
Improper Restriction of XML External Entity Reference vulnerability in SFS Consulting ww.Winsure allows XML Injection.
An XML External Entity (XXE) vulnerability in Dmoz2CSV in openimaj v1.3.10 allows attackers to access sensitive informat
An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information o
An improper restriction of external entities (XXE) vulnerability in dompdf/dompdf's SVG parser allows for Server-Side Re
unstructured v.0.14.2 and before is vulnerable to XML External Entity (XXE) via the XMLParser.
http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 6.50.0.0, there is a potential XXE (XML Ex
An XML External Entity (XXE) injection vulnerability in the component /datagrip/upload of Chat2DB v0.3.5 allows attacker
An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of lxml before v4.9.1 allows attackers
In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for externa
XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file
XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC versions up to 1.0.4 allows
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions are subject to a bypas
Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks.
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: XMLPublisher). Supporte
SAP NetWeaver AS Java (CAF - Guided Procedures) - version 7.50, allows an unauthenticated attacker to submit a malicious
The HL7 FHIR Core Artifacts repository provides the java core object handling code, with utilities (including validator)
The reference validator is a tool to perform advanced validation of FHIR resources for TI applications and interoperabil
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. XSLT parsing pe
Ucum-java is a FHIR Java library providing UCUM Services. In versions prior to 1.0.9, XML parsing performed by the UcumE
Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entit
An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Se
SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. When loading an (untrusted) XML document,
IBM Maximo Application Suite 7.6.1.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML
D-Link D-View addDv7Probe XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows
IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XX
Frequently Asked Questions
What is CWE-611?
CWE-611 (CWE-611) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-611?
There are 1,556 CVE records associated with CWE-611 in our database. Of these, 259 are critical severity, 556 are high severity, and 397 are medium severity.
How can I protect against CWE-611 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-611 using AI-powered security agents.
Detect CWE-611 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-611 vulnerabilities across your infrastructure.
Get Started