CWE-611: CWE-611

238
Total CVEs
67
Critical
135
High
7.9
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
11
2025
54
2024
51
2023
39
2022
32

Top Affected Vendors

1 Ibm 24
2 Apache 10
3 Jenkins 10
4 Adobe 7
5 Microfocus 6
6 Dell 6
7 Ivanti 4
8 Netapp 4
9 Phpoffice 4
10 Jetbrains 3

All CWE-611 CVEs (238)

CVE-2022-22486
10.0

This CVE describes an XML External Entity (XXE) vulnerability in IBM Tivoli Workload Scheduler that allows remote attackers to read arbitrary files on...

Feb 3, 2023
CVE-2025-30220
9.9

This XXE vulnerability in GeoServer's GeoTools Schema class allows attackers to read arbitrary files from the server or perform server-side request fo...

Jun 10, 2025
CVE-2023-27874
9.9

IBM Aspera Faspex 4.4.2 contains an XML external entity injection (XXE) vulnerability that allows authenticated remote attackers to read arbitrary fil...

Mar 21, 2023
CVE-2025-65482
9.8

An XML External Entity (XXE) vulnerability in opensagres XDocReport versions 0.9.2 through 2.0.3 allows attackers to execute arbitrary code by uploadi...

Jan 20, 2026
CVE-2023-38693
9.8

This vulnerability allows remote attackers to execute arbitrary code on Lucee Server by exploiting an XML External Entity (XXE) vulnerability in the R...

Mar 5, 2025
CVE-2024-55081
9.8

An XML External Entity (XXE) injection vulnerability in Chat2DB's /datagrip/upload endpoint allows attackers to read arbitrary files, perform server-s...

Dec 19, 2024
CVE-2024-46455
9.8

CVE-2024-46455 is an XML External Entity (XXE) vulnerability in unstructured's XMLParser that allows attackers to read arbitrary files, perform server...

Dec 9, 2024
CVE-2021-3902
9.8

This XXE vulnerability in dompdf's SVG parser allows attackers to perform Server-Side Request Forgery (SSRF), access internal files, and execute PHAR ...

Nov 15, 2024
CVE-2024-51132
9.8

An XML External Entity (XXE) vulnerability in HAPI FHIR before version 6.4.0 allows attackers to read sensitive files from the server or execute arbit...

Nov 5, 2024
CVE-2024-51136
9.8

This XXE vulnerability in Dmoz2CSV allows attackers to read sensitive files from the server or execute arbitrary code by processing a malicious XML fi...

Nov 4, 2024
CVE-2024-34102
9.8

This critical XXE vulnerability in Adobe Commerce allows unauthenticated attackers to execute arbitrary code by sending malicious XML documents. It af...

Jun 13, 2024
CVE-2024-21082
9.8

This critical vulnerability in Oracle BI Publisher allows unauthenticated attackers with network access via HTTP to completely compromise the system. ...

Apr 16, 2024
CVE-2023-26999
9.8

A critical vulnerability in NetScout nGeniusOne version 6.3.4 allows remote attackers to execute arbitrary code and cause denial of service by uploadi...

Jan 9, 2024
CVE-2023-46265
9.8

This critical vulnerability allows unauthenticated attackers to exploit an XML External Entity (XXE) vulnerability in the Smart Device Server, potenti...

Dec 19, 2023
CVE-2023-49733
9.8

This CVE describes an XXE (XML External Entity) vulnerability in Apache Cocoon that allows attackers to read arbitrary files from the server or perfor...

Nov 30, 2023
CVE-2023-49656
9.8

The Jenkins MATLAB Plugin 2.11.0 and earlier contains an XML External Entity (XXE) vulnerability due to improper XML parser configuration. This allows...

Nov 29, 2023
CVE-2023-46502
9.8

This vulnerability in openCRX v5.2.2 allows remote attackers to read internal files and perform server-side request forgery (SSRF) attacks due to inse...

Oct 30, 2023
CVE-2022-48565
9.8

This CVE describes an XML External Entity (XXE) vulnerability in Python's plistlib module through version 3.9.1. Attackers can exploit this by craftin...

Aug 22, 2023
CVE-2023-20918
9.8

This CVE-2023-20918 is an Android elevation of privilege vulnerability in the ActivityOptions framework. It allows malicious apps to execute arbitrary...

Jul 13, 2023
CVE-2023-24189
9.8

An XML External Entity (XXE) vulnerability in urule v2.1.7 allows attackers to execute arbitrary code by uploading a crafted XML file to the /urule/co...

Feb 24, 2023
CVE-2015-8031
9.8

CVE-2015-8031 is an XML External Entity (XXE) vulnerability in Hudson CI/CD server that allows attackers to read arbitrary files from the server files...

Jul 18, 2022
CVE-2022-35741
9.8

Apache CloudStack versions 4.5.0 and later contain an XML external entity (XXE) injection vulnerability in the SAML 2.0 authentication plugin. This vu...

Jul 18, 2022
CVE-2021-45024
9.8

This vulnerability allows attackers to perform XML External Entity (XXE) attacks on ASG-Zena Cross Platform Server Enterprise Edition 4.2.1. Attackers...

Jun 17, 2022
CVE-2021-41411
9.8

This XML External Entity (XXE) vulnerability in Drools allows attackers to read arbitrary files from the server filesystem or perform server-side requ...

Jun 16, 2022
CVE-2021-45981
9.8

CVE-2021-45981 is an XML External Entity (XXE) vulnerability in NetScout nGeniusONE 6.3.2 that allows attackers to read arbitrary files from the serve...

Jun 2, 2022
CVE-2022-28890
9.8

This vulnerability in Apache Jena's RDF/XML parser allows attackers to force the parser to retrieve external DTDs, potentially leading to XML External...

May 5, 2022
CVE-2022-0272
9.8

This XXE vulnerability in detekt allows attackers to read arbitrary files from the server filesystem or perform server-side request forgery by process...

Apr 21, 2022
CVE-2022-28219
9.8

CVE-2022-28219 is an unauthenticated XML External Entity (XXE) vulnerability in Cewolf within Zoho ManageEngine ADAudit Plus that allows remote attack...

Apr 5, 2022
CVE-2021-43142
9.8

This CVE describes an XML External Entity (XXE) vulnerability in wuta jox 1.16 that allows attackers to read arbitrary files from the server filesyste...

Mar 30, 2022
CVE-2021-43090
9.8

CVE-2021-43090 is an XML External Entity (XXE) vulnerability in soa-model's WSDLParser function that allows attackers to read arbitrary files, conduct...

Mar 25, 2022
CVE-2022-0839
9.8

This vulnerability allows attackers to perform XML External Entity (XXE) attacks through Liquibase, potentially leading to sensitive data disclosure, ...

Mar 4, 2022
CVE-2022-0265
9.8

This XXE vulnerability in Hazelcast 5.1-BETA-1 allows attackers to read arbitrary files from the server filesystem or perform server-side request forg...

Mar 3, 2022
CVE-2022-24340
9.8

This vulnerability allows XML External Entity (XXE) attacks during configuration file parsing in JetBrains TeamCity. Attackers can read arbitrary file...

Feb 25, 2022
CVE-2021-46660
9.8

This vulnerability in Signiant Manager+Agents allows attackers to perform XML External Entity (XXE) attacks by submitting malicious XML input. This co...

Jan 30, 2022
CVE-2022-0239
9.8

CVE-2022-0239 is an XXE (XML External Entity) vulnerability in Stanford CoreNLP that allows attackers to read arbitrary files from the server filesyst...

Jan 17, 2022
CVE-2021-3878
9.8

CVE-2021-3878 is an XML External Entity (XXE) vulnerability in Stanford CoreNLP that allows attackers to read arbitrary files from the server filesyst...

Oct 15, 2021
CVE-2021-38298
9.8

This vulnerability allows attackers to perform blind XML External Entity (XXE) attacks against Zoho ManageEngine ADManager Plus. Attackers can exploit...

Oct 7, 2021
CVE-2020-18703
9.8

CVE-2020-18703 is an XML External Entity (XXE) vulnerability in Quokka CMS v0.4.0 that allows remote attackers to read arbitrary files, perform server...

Aug 16, 2021
CVE-2020-18705
9.8

This CVE describes an XML External Entity (XXE) vulnerability in Quokka CMS v0.4.0 that allows remote attackers to execute arbitrary code by exploitin...

Aug 16, 2021
CVE-2021-35066
9.8

This CVE describes an XML External Entity (XXE) vulnerability in ConnectWise Automate that allows attackers to read arbitrary files from the server fi...

Jun 21, 2021
CVE-2021-1628
9.8

CVE-2021-1628 is an XML External Entity (XXE) vulnerability in Mule runtime that allows attackers to read arbitrary files from the server or perform s...

Mar 26, 2021
CVE-2021-26703
9.8

CVE-2021-26703 is a critical vulnerability in EPrints 3.4.2 that allows remote attackers to read arbitrary files and potentially execute commands via ...

Mar 1, 2021
CVE-2021-23899
9.8

CVE-2021-23899 is a vulnerability in OWASP json-sanitizer versions before 1.2.2 where the sanitizer fails to properly escape closing SCRIPT tags and C...

Jan 13, 2021
CVE-2020-35604
9.8

CVE-2020-35604 is an XML External Entity (XXE) vulnerability in Kronos WebTA 5.0.4 when SAML authentication is configured. This allows attackers to re...

Dec 21, 2020
CVE-2025-49535
9.3

This XXE vulnerability in Adobe ColdFusion allows attackers to bypass security restrictions and access sensitive data or cause denial of service by ex...

Jul 8, 2025
CVE-2025-2775
KEV EPSS 67.8% 9.3

SysAid On-Prem versions up to 23.3.40 contain an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality. This...

May 7, 2025
CVE-2025-2777
EPSS 15.8% 9.3

SysAid On-Prem versions up to 23.3.40 contain an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality. This al...

May 7, 2025
CVE-2025-48006
9.1

This XXE vulnerability in DataSpider Servista allows attackers to read arbitrary files from the server's file system or cause denial-of-service by sen...

Sep 29, 2025
CVE-2025-10183
9.1

CVE-2025-10183 is a blind XML External Entity (XXE) injection vulnerability in TecCom TecConnect 4.1's OpenMessaging webservice that allows unauthenti...

Sep 9, 2025
CVE-2025-46726
9.1

Langroid applications using the XMLToolMessage class with untrusted XML input are vulnerable to XML External Entity (XXE) attacks. This allows attacke...

May 5, 2025

About CWE-611 (CWE-611)

Our database tracks 238 CVEs classified as CWE-611, with 67 rated critical and 135 rated high severity. The average CVSS score for CWE-611 vulnerabilities is 7.9.

External reference: View CWE-611 on MITRE CWE →

Monitor CWE-611 Vulnerabilities

Get alerted when new CWE-611 CVEs affect your infrastructure.

Start Monitoring Free