CWE-611: CWE-611
Yearly Trend
Top Affected Vendors
All CWE-611 CVEs (241)
This CVE describes an XML External Entity (XXE) injection vulnerability in IBM WebSphere Application Server, allowing remote attackers to read sensiti...
Apr 21, 2021This XXE vulnerability in IBM WebSphere Application Server allows remote attackers to read arbitrary files from the server filesystem or cause denial ...
Apr 20, 2021This vulnerability allows authenticated attackers with specific permissions to perform XML External Entity (XXE) attacks against Unica applications by...
Aug 3, 2023This vulnerability in Jenkins Coverage/Complexity Scatter Plot Plugin allows attackers to perform XML External Entity (XXE) attacks by exploiting impr...
Mar 29, 2022The Jenkins Flaky Test Handler Plugin 1.2.1 and earlier contains an XML external entity (XXE) vulnerability due to improper XML parser configuration. ...
Mar 29, 2022This CVE describes an XML External Entity (XXE) vulnerability in IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI. Attackers can exp...
Sep 21, 2021IBM QRadar SIEM versions 7.3 and 7.4 contain an XML External Entity (XXE) vulnerability that allows remote attackers to read sensitive files from the ...
May 5, 2021This CVE describes an XML External Entity (XXE) vulnerability in Aruba AirWave Management Platform that allows remote attackers to read arbitrary file...
Apr 29, 2021An XML External Entities (XXE) vulnerability in the Media Server component of Avaya Equinox Conferencing allows authenticated remote attackers to read...
Apr 28, 2021This CVE describes an XML External Entity (XXE) vulnerability in Aruba AirWave Management Platform that allows remote attackers to read arbitrary file...
Apr 28, 2021This XML External Entity (XXE) vulnerability in Avaya Callback Assist allows authenticated remote attackers to read files on the affected system by pr...
Apr 23, 2021This vulnerability in Jenkins Config File Provider Plugin allows attackers to perform XML External Entity (XXE) attacks by exploiting improper XML par...
Apr 21, 2021This vulnerability allows attackers to perform XML External Entity (XXE) attacks through DTD injection in OpenText Application Automation Tools. Attac...
Oct 16, 2024This vulnerability allows attackers to perform XML External Entity (XXE) attacks through DTD injection in OpenText Application Automation Tools. Attac...
Oct 16, 2024This XXE vulnerability in Liferay Portal and DXP allows authenticated attackers with deployment permissions to read sensitive files or cause denial of...
Feb 20, 2024This XXE vulnerability in Crowd Data Center and Server allows authenticated attackers to read local files and potentially access remote content via XM...
Jan 28, 2026This XXE vulnerability in Schneider Electric's Web Designer configuration tool allows attackers to read sensitive files or potentially execute remote ...
Jan 17, 2025This XML External Entity (XXE) injection vulnerability in OpenText iManager 3.2.6.0200 allows attackers to execute remote code by submitting malicious...
May 28, 2024This CVE describes an XML External Entity (XXE) injection vulnerability in OpenText iManager 3.2.6.0200. Attackers can exploit this vulnerability to r...
May 15, 2024This XXE vulnerability in ureport v2.2.9 allows attackers to execute arbitrary code by uploading a specially crafted XML file to the /ureport/designer...
Feb 14, 2023This XXE vulnerability in Talend Remote Engine Gen 2 allows authenticated users with pipeline editing rights to potentially read sensitive files from ...
Feb 3, 2023This vulnerability in Autodesk Fusion 360 allows attackers to force victims' devices to make arbitrary HTTP requests through malicious SVG files. Atta...
Jul 29, 2022This vulnerability in Magnolia CMS allows attackers to perform XML External Entity (XXE) attacks by uploading a malicious XLF file through the Export ...
Feb 11, 2022This vulnerability in Intel Quartus Prime Pro Edition allows authenticated local users to exploit improper XML external entity (XXE) restrictions, pot...
Feb 9, 2022This vulnerability allows authenticated XWiki users to exploit the JIRA macro to read arbitrary local files on the XWiki server via XML External Entit...
Apr 3, 2025Pega Platform versions 6.x through 8.8.4 contain an XML External Entity (XXE) vulnerability in PDF generation functionality. This allows attackers to ...
Mar 14, 2024This vulnerability allows unauthenticated attackers to send specially-crafted XML messages to Splunk's SAML authentication parser, causing a denial of...
Jun 1, 2023CVE-2021-42776 is an XML External Entity (XXE) vulnerability in CloverDX Server that allows attackers to read arbitrary files on the server during con...
Dec 1, 2021This XXE vulnerability in Dell Unisphere for PowerMax allows low-privileged remote attackers to access unauthorized data and resources by exploiting i...
Jan 6, 2026The Demo Importer Plus WordPress plugin contains an XML External Entity Injection vulnerability in SVG file upload functionality. Authenticated attack...
Jan 17, 2026This XML external entity (XXE) injection vulnerability in eyoucms v1.7.1 allows remote attackers to cause denial of service by sending specially craft...
Dec 3, 2025N-central versions before 2025.4 are vulnerable to XML External Entity (XXE) injection attacks, allowing attackers to read arbitrary files from the se...
Nov 12, 2025The CycloneDX core Java library's XML validator is vulnerable to XML External Entity (XXE) injection due to insecure configuration. This allows attack...
Nov 10, 2025This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in MetInfo CMS that can be triggered via XML External Entity (XXE) injection. At...
Nov 6, 2025Xerox FreeFlow Core version 8.0.4 has an XML External Entity (XXE) vulnerability that allows Server-Side Request Forgery (SSRF). Attackers can inject ...
Aug 8, 2025Keyoti SearchUnit versions before 9.0.0 are vulnerable to XML External Entity (XXE) attacks. This allows attackers who can submit malicious XML/DTD fi...
Jun 10, 2025TEIGarage's Document Conversion Service contains a critical XML External Entity (XXE) Injection vulnerability that allows attackers to read arbitrary ...
Apr 15, 2025An XML External Entity (XXE) vulnerability in Apache Ambari/Oozie allows attackers to inject malicious XML entities due to insecure parsing with Docum...
Jan 21, 2025An XML External Entity (XXE) vulnerability in Elspec G5 digital fault recorder versions 1.2.1.12 and earlier allows attackers to cause Denial of Servi...
Jan 7, 2025An XML External Entity (XXE) vulnerability in Elspec Engineering G5 Digital Fault Recorder firmware allows attackers to cause Denial of Service (DoS) ...
Jan 7, 2025CVE-2023-24466 is an XML External Entity (XXE) injection vulnerability in OpenText iManager's GET parameter processing. Attackers can exploit this to ...
Nov 22, 2024This vulnerability allows attackers to bypass XML external entity (XXE) protection in PhpSpreadsheet by using UTF-7 encoding tricks. Attackers can rea...
Nov 18, 2024This vulnerability allows attackers to bypass XML external entity (XXE) protection in PhpSpreadsheet by exploiting UCS-4 encoding and encoding guessin...
Nov 18, 2024This vulnerability in PHPSpreadsheet allows attackers to bypass XML security scanning by using whitespace manipulation in XLSX files, enabling XXE att...
Oct 7, 2024DataEase versions before 2.10.1 contain an XML external entity injection (XXE) vulnerability in the static resource upload interface. This allows atta...
Sep 23, 2024This XXE vulnerability in soap_cgi.pyc allows unauthenticated attackers to read local files, perform SSRF attacks, and potentially cause denial of ser...
Aug 8, 2024This vulnerability allows attackers to perform XML External Entity (XXE) injection attacks when processing CycloneDX SBOM files in XML format. It affe...
Jun 28, 2024An XML External Entity (XXE) vulnerability in ebookmeta's get_metadata function allows attackers to read sensitive files from the server or cause deni...
Jun 7, 2024This XXE vulnerability in LG Simple Editor allows remote attackers to read arbitrary files from the system without authentication. Attackers can explo...
May 3, 2024This vulnerability in LG Simple Editor allows remote attackers to read sensitive files from the system without authentication by exploiting an XML Ext...
May 3, 2024About CWE-611 (CWE-611)
Our database tracks 241 CVEs classified as CWE-611, with 68 rated critical and 137 rated high severity. The average CVSS score for CWE-611 vulnerabilities is 7.9.
External reference: View CWE-611 on MITRE CWE →
Monitor CWE-611 Vulnerabilities
Get alerted when new CWE-611 CVEs affect your infrastructure.
Start Monitoring Free