CWE-611: CWE-611

246
Total CVEs
72
Critical
138
High
7.9
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
11
2025
54
2024
51
2023
39
2022
32

Top Affected Vendors

1 Ibm 27
2 Apache 10
3 Jenkins 10
4 Adobe 7
5 Dell 6
6 Microfocus 6
7 Ivanti 4
8 Netapp 4
9 Phpoffice 4
10 Wso2 4

All CWE-611 CVEs (246)

CVE-2024-38374
7.5

This vulnerability allows attackers to perform XML External Entity (XXE) injection attacks when processing CycloneDX SBOM files in XML format. It affe...

Jun 28, 2024
CVE-2024-36827
7.5

An XML External Entity (XXE) vulnerability in ebookmeta's get_metadata function allows attackers to read sensitive files from the server or cause deni...

Jun 7, 2024
CVE-2023-40506
7.5

This XXE vulnerability in LG Simple Editor allows remote attackers to read arbitrary files from the system without authentication. Attackers can explo...

May 3, 2024
CVE-2023-40503
7.5

This vulnerability in LG Simple Editor allows remote attackers to read sensitive files from the system without authentication by exploiting an XML Ext...

May 3, 2024
CVE-2023-22274
7.5

An unauthenticated attacker can exploit this XXE vulnerability in Adobe RoboHelp Server to read sensitive files from the server filesystem. This affec...

Nov 17, 2023
CVE-2023-38343
7.5

This XXE vulnerability in Ivanti Endpoint Manager's CSEP component allows attackers to read arbitrary files or perform SSRF attacks by exploiting impr...

Sep 21, 2023
CVE-2023-40239
7.5

This vulnerability in certain Lexmark devices allows XML External Entity (XXE) attacks, which can lead to information disclosure by reading files from...

Sep 1, 2023
CVE-2020-26709
7.5

CVE-2020-26709 is an XML External Entity (XXE) vulnerability in py-xml v1.0 that allows attackers to execute arbitrary code by processing a malicious ...

Jun 29, 2023
CVE-2023-27527
7.5

Shinseiyo Sogo Soft versions 7.9A and earlier contain an XML External Entity (XXE) vulnerability that allows attackers to read arbitrary files on the ...

May 10, 2023
CVE-2022-38840
7.5

CVE-2022-38840 is an XML External Entity (XXE) vulnerability in the xmlstatus.cgi component of GΓΌralp MAN-EAM-0003 seismic monitoring systems. It all...

Apr 16, 2023
CVE-2023-28680
7.5

The Jenkins Crap4J Plugin 0.9 and earlier contains an XML external entity (XXE) vulnerability due to improper XML parser configuration. This allows at...

Apr 2, 2023
CVE-2021-33950
7.5

CVE-2021-33950 is an XML external entity (XXE) vulnerability in OpenKM document management system that allows attackers to extract sensitive informati...

Feb 17, 2023
CVE-2023-22832
7.5

This vulnerability allows XML External Entity (XXE) attacks in Apache NiFi's ExtractCCDAAttributes Processor. Attackers can exploit this to read arbit...

Feb 10, 2023
CVE-2022-2414
7.5

CVE-2022-2414 is an XML External Entity (XXE) vulnerability in Dogtag PKI software that allows attackers to read arbitrary files on the server by subm...

Jul 29, 2022
CVE-2022-31471
7.5

CVE-2022-31471 is an XML External Entity (XXE) vulnerability in the untangle Python library that allows attackers to read local files on systems proce...

Jul 26, 2022
CVE-2022-32458
7.5

Digiwin BPM has an XML External Entity (XXE) vulnerability that allows unauthenticated remote attackers to read arbitrary files on the server. This af...

Jul 20, 2022
CVE-2021-40510
7.5

CVE-2021-40510 is an XML External Entity (XXE) vulnerability in OBDA Systems' Mastro 1.0 that allows remote attackers to read arbitrary system files b...

Jun 21, 2022
CVE-2021-20838
7.5

This vulnerability allows remote unauthenticated attackers to conduct XML External Entity (XXE) attacks against Office Server Document Converter, pote...

Nov 1, 2021
CVE-2021-3869
7.5

CVE-2021-3869 is an XXE (XML External Entity) vulnerability in Stanford CoreNLP that allows attackers to read arbitrary files from the server filesyst...

Oct 19, 2021
CVE-2021-39371
7.5

This CVE describes an XML External Entity (XXE) injection vulnerability in PyWPS and potentially OWSLib. It allows attackers to read arbitrary files o...

Aug 23, 2021
CVE-2021-1630
7.5

This CVE describes an XML External Entity (XXE) vulnerability in certain Mule runtime components that allows attackers to read arbitrary files from th...

Aug 5, 2021
CVE-2021-30201
7.5

This is an XML External Entity (XXE) vulnerability in Kaseya VSA's web service API that allows attackers to read arbitrary files on the server and pot...

Jul 9, 2021
CVE-2012-1102
7.5

CVE-2012-1102 is an XML External Entity (XXE) vulnerability in XML::Atom Perl module versions before 0.39. It allows attackers to read protected files...

Jul 9, 2021
CVE-2021-25951
7.5

CVE-2021-25951 is an XML External Entity (XXE) vulnerability in XML2Dict version 0.2.2 that allows attackers to cause denial of service by parsing mal...

Jun 30, 2021
CVE-2021-29620
7.5

This CVE describes an XML External Entity (XXE) vulnerability in Report Portal's service-api module. It allows attackers to upload specially crafted X...

Jun 23, 2021
CVE-2021-22140
7.5

This XXE vulnerability in Elastic App Search's web crawler beta feature allows attackers to read sensitive files on the host system. Attackers can exp...

May 13, 2021
CVE-2021-30006
7.5

This CVE describes an XML External Entity (XXE) vulnerability in IntelliJ IDEA that allows attackers to read arbitrary files from the system. It affec...

May 11, 2021
CVE-2021-29421
7.5

This vulnerability in pikepdf allows XML External Entity (XXE) attacks when parsing XMP metadata in PDF files. Attackers can exploit this to read arbi...

Apr 1, 2021
CVE-2021-27184
7.5

This CVE describes an XML External Entity (XXE) vulnerability in Pelco Digital Sentry Server version 7.18.72.11464. Attackers can exploit this to read...

Feb 11, 2021
CVE-2019-1057
7.5

This CVE describes a remote code execution vulnerability in Microsoft XML Core Services (MSXML) parser that allows attackers to run arbitrary code on ...

Aug 14, 2019
CVE-2023-22377
7.4

This XXE vulnerability in tsClinical software allows attackers to read arbitrary files on the system by processing specially crafted XML files. It aff...

Feb 15, 2023
CVE-2024-56322
7.2

GoCD versions 16.7.0 through 24.4.0 contain an XML External Entity (XXE) injection vulnerability in a hidden configuration repository feature. This al...

Jan 3, 2025
CVE-2023-49110
7.2

This XXE vulnerability in Kiuwan SAST allows authenticated attackers to read arbitrary files from the server and perform internal network reconnaissan...

Jun 20, 2024
CVE-2021-42194
7.2

This XXE vulnerability in EyouCMS allows attackers to read sensitive files from the server or perform server-side request forgery by sending malicious...

Mar 20, 2022
CVE-2021-38584
7.2

This vulnerability allows XML External Entity (XXE) attacks through the WHM Locale Upload feature in cPanel. Attackers can exploit this to read arbitr...

Aug 11, 2021
CVE-2021-22158
7.2

This XXE vulnerability in Proofpoint Insider Threat Management Server allows authenticated admin users with knowledge of the XML encryption key to rea...

Apr 6, 2021
CVE-2021-21517
7.2

CVE-2021-21517 is an XML External Entity Injection (XXE) vulnerability in Dell EMC SRS Policy Manager 6.X that allows remote unauthenticated attackers...

Mar 1, 2021
CVE-2026-1567
7.1

This XML External Entity (XXE) vulnerability in IBM InfoSphere Information Server allows attackers to read sensitive files from the server by exploiti...

Mar 3, 2026
CVE-2025-36247
7.1

IBM Db2 databases running vulnerable versions are susceptible to XML external entity injection (XXE) attacks when processing XML data. This allows rem...

Feb 17, 2026
CVE-2026-22186
7.1

Bio-Formats up to version 8.3.0 contains an XML External Entity (XXE) vulnerability in the Leica Microsystems metadata parser. This allows attackers t...

Jan 7, 2026
CVE-2025-63917
7.1

PDFPatcher versions up to 1.1.3.4663 contain an XML External Entity (XXE) vulnerability in the XML bookmark import functionality. Attackers can exploi...

Nov 17, 2025
CVE-2025-12531
7.1

IBM InfoSphere Information Server versions 11.7.0.0 through 11.7.1.6 contain an XML external entity injection (XXE) vulnerability that allows remote a...

Nov 3, 2025
CVE-2025-64134
7.1

Jenkins JDepend Plugin 1.3.1 and earlier contains an XML external entity (XXE) vulnerability due to an outdated JDepend Maven Plugin dependency. This ...

Oct 29, 2025
CVE-2024-49781
7.1

IBM OpenPages with Watson versions 8.3 and 9.0 contain an XML external entity injection (XXE) vulnerability that allows attackers to read sensitive fi...

Feb 20, 2025
CVE-2024-54171
7.1

IBM EntireX 11.1 has an XML external entity injection vulnerability that allows authenticated attackers to read sensitive files from the server or cau...

Feb 6, 2025
CVE-2024-49352
7.1

IBM Cognos Analytics is vulnerable to XML External Entity Injection (XXE), allowing attackers to read sensitive files from the server or cause denial ...

Feb 5, 2025
CVE-2024-56324
7.1

GoCD versions before 24.5.0 contain an XML External Entity (XXE) vulnerability that allows group administrators to inject malicious XML when editing p...

Jan 3, 2025
CVE-2024-29010
7.1

This XXE vulnerability in GMS ECM URL endpoint allows attackers to process malicious XML documents that can reference external entities, potentially l...

May 1, 2024
CVE-2023-32327
7.1

This CVE describes an XML External Entity (XXE) vulnerability in IBM Security Access Manager Container products. Attackers can exploit this by submitt...

Feb 3, 2024
CVE-2023-35892
7.1

IBM Financial Transaction Manager for SWIFT Services 3.2.4 has an XML External Entity (XXE) vulnerability that allows attackers to read sensitive file...

Sep 5, 2023

About CWE-611 (CWE-611)

Our database tracks 246 CVEs classified as CWE-611, with 72 rated critical and 138 rated high severity. The average CVSS score for CWE-611 vulnerabilities is 7.9.

External reference: View CWE-611 on MITRE CWE →

Monitor CWE-611 Vulnerabilities

Get alerted when new CWE-611 CVEs affect your infrastructure.

Start Monitoring Free