CWE-611: CWE-611

249
Total CVEs
72
Critical
141
High
7.9
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
11
2025
54
2024
51
2023
39
2022
32

Top Affected Vendors

1 Ibm 28
2 Apache 11
3 Jenkins 11
4 Adobe 7
5 Dell 6
6 Microfocus 6
7 Netapp 5
8 Oracle 4
9 Ivanti 4
10 Phpoffice 4

All CWE-611 CVEs (249)

CVE-2024-29010
7.1

This XXE vulnerability in GMS ECM URL endpoint allows attackers to process malicious XML documents that can reference external entities, potentially l...

May 1, 2024
CVE-2023-32327
7.1

This CVE describes an XML External Entity (XXE) vulnerability in IBM Security Access Manager Container products. Attackers can exploit this by submitt...

Feb 3, 2024
CVE-2023-35892
7.1

IBM Financial Transaction Manager for SWIFT Services 3.2.4 has an XML External Entity (XXE) vulnerability that allows attackers to read sensitive file...

Sep 5, 2023
CVE-2022-41221
7.1

This XXE vulnerability in OpenText Archive Center Administration allows authenticated users to upload malicious XML files that can lead to data exfilt...

May 24, 2023
CVE-2023-28008
7.1

HCL Workload Automation versions 9.4, 9.5, and 10.1 contain an XML External Entity (XXE) vulnerability that allows remote attackers to read sensitive ...

Apr 26, 2023
CVE-2023-27876
7.1

IBM TRIRIGA 4.0 has an XML external entity injection (XXE) vulnerability that allows attackers to read sensitive files from the server or cause denial...

Apr 7, 2023
CVE-2022-36969
7.1

This XXE vulnerability in AVEVA Edge 2020 allows attackers to read sensitive files from the system when users open malicious documents. Attackers can ...

Mar 29, 2023
CVE-2022-22977
7.1

This CVE describes an XML External Entity (XXE) vulnerability in VMware Tools for Windows that allows a malicious actor with non-administrative local ...

May 24, 2022
CVE-2019-4730
7.1

IBM Cognos Analytics 11.0 and 11.1 contains an XML External Entity (XXE) vulnerability that allows remote attackers to read arbitrary files from the s...

Jun 1, 2021
CVE-2021-29447
7.1

WordPress users with file upload permissions (like Authors) can exploit an XML parsing vulnerability in the Media Library to perform XXE attacks when ...

Apr 15, 2021
CVE-2021-20502
7.1

This XXE vulnerability in IBM Jazz Foundation Products allows attackers to read sensitive files from the server or cause denial of service through mem...

Mar 30, 2021
CVE-2021-20482
7.1

This XXE vulnerability in IBM Cloud Pak for Automation allows attackers to read sensitive files from the server or cause denial of service by consumin...

Mar 30, 2021
CVE-2024-22354
7.0

This XML External Entity Injection (XXE) vulnerability in IBM WebSphere Application Server allows attackers to process malicious XML data, potentially...

Apr 17, 2024
CVE-2025-61821
6.8

This XXE vulnerability in ColdFusion allows attackers to read arbitrary files from the server's filesystem without user interaction. It affects ColdFu...

Dec 10, 2025
CVE-2025-25036
6.8

This CVE describes an XML External Entity (XXE) vulnerability in Jalios JPlatform that allows attackers to read arbitrary files from the server, poten...

Mar 21, 2025
CVE-2025-10713
6.5

An XML External Entity (XXE) vulnerability in multiple WSO2 products allows attackers to read sensitive server files or cause denial-of-service. The v...

Nov 5, 2025
CVE-2025-46425
6.5

This XXE vulnerability in Dell Storage Manager allows attackers to read arbitrary files on the server or potentially cause denial of service. It affec...

Oct 24, 2025
CVE-2024-5625
6.5

This XXE vulnerability in PruvaSoft Informatics Apinizer Management Console allows attackers to read arbitrary files from the server or cause denial o...

Jul 18, 2024
CVE-2024-4357
6.5

This CVE describes an XML External Entity (XXE) vulnerability in Progress Telerik Report Server that allows low-privilege authenticated attackers to r...

May 15, 2024
CVE-2023-51605
6.5

This XXE vulnerability in Honeywell Saia PG5 Controls Suite allows attackers to read sensitive files from the system when users open malicious XML fil...

May 3, 2024
CVE-2023-51601
6.5

This XXE vulnerability in Honeywell Saia PG5 Controls Suite allows attackers to disclose sensitive information by tricking users into opening maliciou...

May 3, 2024
CVE-2024-3930
6.3

This CVE describes an XML External Entity (XXE) vulnerability in Akana API Platform versions before 2024.1.0. Attackers can exploit this flaw to read ...

Jul 30, 2024
CVE-2025-61823
6.2

This XXE vulnerability in Adobe ColdFusion allows high-privileged attackers to read arbitrary files from the server filesystem when they can submit ma...

Dec 10, 2025
CVE-2025-57704
5.5

Delta Electronics EIP Builder version 1.11 contains an XML External Entity (XXE) vulnerability that allows attackers to read arbitrary files from the ...

Aug 26, 2025
CVE-2025-26484
5.5

Dell CloudLink versions 8.0 through 8.1.1 contain an XML External Entity (XXE) vulnerability that allows high-privileged attackers with remote access ...

Aug 14, 2025
CVE-2025-40584
5.5

This CVE describes an XML External Entity (XXE) injection vulnerability in multiple Siemens SIMOTION and SINAMICS engineering software versions. Attac...

Aug 12, 2025
CVE-2024-12298
5.5

This vulnerability in NB-series NX-Designer allows attackers to exploit XML External Entity (XXE) processing to read arbitrary files from the system. ...

Jan 14, 2025
CVE-2024-49704
5.5

This XXE vulnerability in Siemens COMOS software allows attackers to read arbitrary files from affected systems by tricking users into opening malicio...

Dec 10, 2024
CVE-2024-20531
5.5

This vulnerability in Cisco ISE allows authenticated attackers with Super Admin credentials to read arbitrary files on the underlying OS and conduct S...

Nov 6, 2024
CVE-2024-45072
5.5

IBM WebSphere Application Server 8.5 and 9.0 contains an XML External Entity (XXE) vulnerability that allows privileged users to read arbitrary files ...

Oct 16, 2024
CVE-2019-1187
5.5

This is a denial of service vulnerability in Microsoft's XmlLite runtime library that improperly parses XML input. An attacker can crash XML applicati...

Aug 14, 2019
CVE-2024-47582
5.3

This CVE describes an XML Entity Expansion (XXE) vulnerability in SAP software where unauthenticated attackers can send malicious XML input to an endp...

Dec 10, 2024
CVE-2023-28150
5.3

This vulnerability allows attackers to perform XML External Entity (XXE) injection attacks by uploading malicious DOCX files containing remote DTD ref...

Mar 24, 2023
CVE-2023-28151
5.3

This vulnerability in Independentsoft JSpreadsheet allows attackers to perform XML External Entity (XXE) injection by uploading a malicious DOCX file ...

Mar 24, 2023
CVE-2024-58335
5.0

OpenXRechnungToolbox contains an XML External Entity (XXE) vulnerability in its visualization component that allows attackers to read arbitrary files ...

Dec 24, 2025
CVE-2025-66370
5.0

Kivitendo ERP software versions before 3.9.2 contain an XML External Entity (XXE) injection vulnerability in the ZUGFeRD electronic invoice upload fun...

Nov 28, 2025
CVE-2025-66371
5.0

CVE-2025-66371 is an XML External Entity (XXE) vulnerability in peppol-py versions before 1.1.1. It allows attackers to read arbitrary files from the ...

Nov 28, 2025
CVE-2024-45745
5.0

This vulnerability allows authenticated attackers in TopQuadrant TopBraid EDG to upload XML DTD files containing malicious JavaScript, enabling them t...

Sep 27, 2024
CVE-2026-23795
4.9

This CVE describes an XXE vulnerability in Apache Syncope Console that allows administrators with Keymaster parameter privileges to inject malicious X...

Feb 3, 2026
CVE-2026-20029
4.9

An XML External Entity (XXE) vulnerability in Cisco ISE and ISE-PIC allows authenticated administrators to read arbitrary files on the underlying oper...

Jan 7, 2026
CVE-2025-68463
4.9

This vulnerability in Biopython's Bio.Entrez module allows XML External Entity (XXE) attacks through improper restriction of XML doctype declarations....

Dec 18, 2025
CVE-2025-24910
4.9

This vulnerability allows attackers to perform XML External Entity (XXE) attacks against Hitachi Vantara Pentaho Business Analytics Server. By submitt...

Apr 16, 2025
CVE-2025-24521
4.9

This CVE describes an XML External Entity (XXE) injection vulnerability that allows attackers to read arbitrary files from affected systems. It affect...

Mar 5, 2025
CVE-2025-49539
4.5

This XXE vulnerability in Adobe ColdFusion allows high-privileged attackers to bypass security restrictions and access sensitive information without u...

Jul 8, 2025
CVE-2025-36603
4.2

This vulnerability in Dell AppSync 4.6.0.0 allows a low-privileged attacker with local access to exploit an XML External Entity (XXE) flaw, potentiall...

Jul 21, 2025
CVE-2025-35112
4.1

Agiloft Release 28 contains an XML External Entities (XXE) vulnerability in import/export functionality that allows authenticated attackers to perform...

Aug 26, 2025
CVE-2025-66372
2.8

CVE-2025-66372 is an XML External Entity (XXE) vulnerability in Mustang library versions before 2.16.3 that allows attackers to exfiltrate files from ...

Nov 28, 2025
CVE-2026-23739
2.0

This CVE describes an XML External Entity (XXE) vulnerability in Asterisk's XML parsing function. It allows attackers to read sensitive files from the...

Feb 6, 2026
CVE-2026-1227
N/A

This XXE vulnerability in Schneider Electric's EBO system allows attackers to read local files, interact with internal systems, or cause denial of ser...

Feb 11, 2026

About CWE-611 (CWE-611)

Our database tracks 249 CVEs classified as CWE-611, with 72 rated critical and 141 rated high severity. The average CVSS score for CWE-611 vulnerabilities is 7.9.

External reference: View CWE-611 on MITRE CWE →

Monitor CWE-611 Vulnerabilities

Get alerted when new CWE-611 CVEs affect your infrastructure.

Start Monitoring Free