Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-611

MITRE ↗

CWE-611

259
CRITICAL
556
HIGH
397
MEDIUM
22
LOW
1,259 CVEs · Page 5/26
4.9
CVE-2025-24521

External XML entity injection allows arbitrary download of files. The score without least privilege principle violation

4.9
CVE-2025-24910

Overview   XML documents optionally contain a Document Type Definition (DTD), which, among other features, enable

4.9
CVE-2025-24911

Overview   XML documents optionally contain a Document Type Definition (DTD), which, among other features, enable

4.9
CVE-2025-68463

Bio.Entrez in Biopython through 186 allows doctype XXE.

4.6
CVE-2025-20369

In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.

4.5
CVE-2025-49539

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity

4.3
CVE-2024-25066

RSA Authentication Manager before 8.7 SP2 Patch 1 allows XML External Entity (XXE) attacks via a license file, resulting

4.2
CVE-2025-36603

Dell AppSync, version(s) 4.6.0.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low

4.1
CVE-2025-29932

In JetBrains GoLand before 2025.1 an XXE during debugging was possible

4.1
CVE-2025-35112

Agiloft Release 28 contains an XML External Entities vulnerability in any table that allows 'import/export', allowing an

2.8
CVE-2025-66372

Mustang before 2.16.3 allows exfiltrating files via XXE attacks.

2.5
CVE-2024-42185

BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML injection attacks. This

CVE-2025-27136

LocalS3 is an Amazon S3 mock service for testing and local development. Prior to version 1.21, the LocalS3 service's buc

CVE-2025-47778

Sulu is an open-source PHP content management system based on the Symfony framework. Starting in versions 2.5.21, 2.6.5,

CVE-2025-4639

CWE-611 Improper Restriction of XML External Entity Reference in the getDocumentBuilder() method of WebDav servlet in Pe

CVE-2025-4641

Improper Restriction of XML External Entity Reference vulnerability in bonigarcia webdrivermanager WebDriverManager on W

CVE-2025-48882

PHPOffice Math is a library that provides a set of classes to manipulate different formula file formats. Prior to versio

CVE-2025-47293

PowSyBl (Power System Blocks) is a framework to build power system oriented software. Prior to version 6.7.2, in certain

CVE-2025-6438

A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause manipulati

CVE-2025-34142

An XML External Entity (XXE) injection vulnerability exists in ETQ Reliance on the CG (legacy) platform within the `/res

CVE-2025-54992

OpenKilda is an open-source OpenFlow controller. Prior to version 1.164.0, an XML external entity (XXE) injection vulner

CVE-2023-7307

Sangfor Behavior Management System (also referred to as DC Management System in Chinese-language documentation) contains

9.8
CVE-2023-26999

An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code and cause a denial of s

9.8
CVE-2024-21082

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that

9.8
CVE-2024-34102 KEV

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML E

9.8
CVE-2024-7098

Improper Restriction of XML External Entity Reference vulnerability in SFS Consulting ww.Winsure allows XML Injection.

9.8
CVE-2024-51136

An XML External Entity (XXE) vulnerability in Dmoz2CSV in openimaj v1.3.10 allows attackers to access sensitive informat

9.8
CVE-2024-51132

An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information o

9.8
CVE-2021-3902

An improper restriction of external entities (XXE) vulnerability in dompdf/dompdf's SVG parser allows for Server-Side Re

9.8
CVE-2024-46455

unstructured v.0.14.2 and before is vulnerable to XML External Entity (XXE) via the XMLParser.

9.8
CVE-2024-55875

http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 6.50.0.0, there is a potential XXE (XML Ex

9.8
CVE-2024-55081

An XML External Entity (XXE) injection vulnerability in the component /datagrip/upload of Chat2DB v0.3.5 allows attacker

9.1
CVE-2024-37388

An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of lxml before v4.9.1 allows attackers

9.1
CVE-2024-40896

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for externa

8.8
CVE-2023-48362

XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file

8.8
CVE-2024-22218

XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC versions up to 1.0.4 allows

8.8
CVE-2024-45048

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions are subject to a bypas

8.8
CVE-2023-37233

Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks.

8.8
CVE-2024-21255

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: XMLPublisher). Supporte

8.6
CVE-2024-24743

SAP NetWeaver AS Java (CAF - Guided Procedures) - version 7.50, allows an unauthenticated attacker to submit a malicious

8.6
CVE-2024-45294

The HL7 FHIR Core Artifacts repository provides the java core object handling code, with utilities (including validator)

8.6
CVE-2024-46984

The reference validator is a tool to perform advanced validation of FHIR resources for TI applications and interoperabil

8.6
CVE-2024-52007

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. XSLT parsing pe

8.6
CVE-2024-55887

Ucum-java is a FHIR Java library providing UCUM Services. In versions prior to 1.0.9, XML parsing performed by the UcumE

8.5
CVE-2024-10839

Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entit

8.3
CVE-2024-22024

An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Se

8.3
CVE-2024-52806

SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. When loading an (untrusted) XML document,

8.2
CVE-2024-27266

IBM Maximo Application Suite 7.6.1.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML

8.2
CVE-2023-44412

D-Link D-View addDv7Probe XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows

8.2
CVE-2023-45192

IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XX

Frequently Asked Questions

What is CWE-611?

CWE-611 (CWE-611) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-611?

There are 1,556 CVE records associated with CWE-611 in our database. Of these, 259 are critical severity, 556 are high severity, and 397 are medium severity.

How can I protect against CWE-611 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-611 using AI-powered security agents.

Detect CWE-611 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-611 vulnerabilities across your infrastructure.

Get Started