CWE-611: CWE-611
Yearly Trend
Top Affected Vendors
All CWE-611 CVEs (249)
This XXE vulnerability in GMS ECM URL endpoint allows attackers to process malicious XML documents that can reference external entities, potentially l...
May 1, 2024This CVE describes an XML External Entity (XXE) vulnerability in IBM Security Access Manager Container products. Attackers can exploit this by submitt...
Feb 3, 2024IBM Financial Transaction Manager for SWIFT Services 3.2.4 has an XML External Entity (XXE) vulnerability that allows attackers to read sensitive file...
Sep 5, 2023This XXE vulnerability in OpenText Archive Center Administration allows authenticated users to upload malicious XML files that can lead to data exfilt...
May 24, 2023HCL Workload Automation versions 9.4, 9.5, and 10.1 contain an XML External Entity (XXE) vulnerability that allows remote attackers to read sensitive ...
Apr 26, 2023IBM TRIRIGA 4.0 has an XML external entity injection (XXE) vulnerability that allows attackers to read sensitive files from the server or cause denial...
Apr 7, 2023This XXE vulnerability in AVEVA Edge 2020 allows attackers to read sensitive files from the system when users open malicious documents. Attackers can ...
Mar 29, 2023This CVE describes an XML External Entity (XXE) vulnerability in VMware Tools for Windows that allows a malicious actor with non-administrative local ...
May 24, 2022IBM Cognos Analytics 11.0 and 11.1 contains an XML External Entity (XXE) vulnerability that allows remote attackers to read arbitrary files from the s...
Jun 1, 2021WordPress users with file upload permissions (like Authors) can exploit an XML parsing vulnerability in the Media Library to perform XXE attacks when ...
Apr 15, 2021This XXE vulnerability in IBM Jazz Foundation Products allows attackers to read sensitive files from the server or cause denial of service through mem...
Mar 30, 2021This XXE vulnerability in IBM Cloud Pak for Automation allows attackers to read sensitive files from the server or cause denial of service by consumin...
Mar 30, 2021This XML External Entity Injection (XXE) vulnerability in IBM WebSphere Application Server allows attackers to process malicious XML data, potentially...
Apr 17, 2024This XXE vulnerability in ColdFusion allows attackers to read arbitrary files from the server's filesystem without user interaction. It affects ColdFu...
Dec 10, 2025This CVE describes an XML External Entity (XXE) vulnerability in Jalios JPlatform that allows attackers to read arbitrary files from the server, poten...
Mar 21, 2025An XML External Entity (XXE) vulnerability in multiple WSO2 products allows attackers to read sensitive server files or cause denial-of-service. The v...
Nov 5, 2025This XXE vulnerability in Dell Storage Manager allows attackers to read arbitrary files on the server or potentially cause denial of service. It affec...
Oct 24, 2025This XXE vulnerability in PruvaSoft Informatics Apinizer Management Console allows attackers to read arbitrary files from the server or cause denial o...
Jul 18, 2024This CVE describes an XML External Entity (XXE) vulnerability in Progress Telerik Report Server that allows low-privilege authenticated attackers to r...
May 15, 2024This XXE vulnerability in Honeywell Saia PG5 Controls Suite allows attackers to read sensitive files from the system when users open malicious XML fil...
May 3, 2024This XXE vulnerability in Honeywell Saia PG5 Controls Suite allows attackers to disclose sensitive information by tricking users into opening maliciou...
May 3, 2024This CVE describes an XML External Entity (XXE) vulnerability in Akana API Platform versions before 2024.1.0. Attackers can exploit this flaw to read ...
Jul 30, 2024This XXE vulnerability in Adobe ColdFusion allows high-privileged attackers to read arbitrary files from the server filesystem when they can submit ma...
Dec 10, 2025Delta Electronics EIP Builder version 1.11 contains an XML External Entity (XXE) vulnerability that allows attackers to read arbitrary files from the ...
Aug 26, 2025Dell CloudLink versions 8.0 through 8.1.1 contain an XML External Entity (XXE) vulnerability that allows high-privileged attackers with remote access ...
Aug 14, 2025This CVE describes an XML External Entity (XXE) injection vulnerability in multiple Siemens SIMOTION and SINAMICS engineering software versions. Attac...
Aug 12, 2025This vulnerability in NB-series NX-Designer allows attackers to exploit XML External Entity (XXE) processing to read arbitrary files from the system. ...
Jan 14, 2025This XXE vulnerability in Siemens COMOS software allows attackers to read arbitrary files from affected systems by tricking users into opening malicio...
Dec 10, 2024This vulnerability in Cisco ISE allows authenticated attackers with Super Admin credentials to read arbitrary files on the underlying OS and conduct S...
Nov 6, 2024IBM WebSphere Application Server 8.5 and 9.0 contains an XML External Entity (XXE) vulnerability that allows privileged users to read arbitrary files ...
Oct 16, 2024This is a denial of service vulnerability in Microsoft's XmlLite runtime library that improperly parses XML input. An attacker can crash XML applicati...
Aug 14, 2019This CVE describes an XML Entity Expansion (XXE) vulnerability in SAP software where unauthenticated attackers can send malicious XML input to an endp...
Dec 10, 2024This vulnerability allows attackers to perform XML External Entity (XXE) injection attacks by uploading malicious DOCX files containing remote DTD ref...
Mar 24, 2023This vulnerability in Independentsoft JSpreadsheet allows attackers to perform XML External Entity (XXE) injection by uploading a malicious DOCX file ...
Mar 24, 2023OpenXRechnungToolbox contains an XML External Entity (XXE) vulnerability in its visualization component that allows attackers to read arbitrary files ...
Dec 24, 2025Kivitendo ERP software versions before 3.9.2 contain an XML External Entity (XXE) injection vulnerability in the ZUGFeRD electronic invoice upload fun...
Nov 28, 2025CVE-2025-66371 is an XML External Entity (XXE) vulnerability in peppol-py versions before 1.1.1. It allows attackers to read arbitrary files from the ...
Nov 28, 2025This vulnerability allows authenticated attackers in TopQuadrant TopBraid EDG to upload XML DTD files containing malicious JavaScript, enabling them t...
Sep 27, 2024This CVE describes an XXE vulnerability in Apache Syncope Console that allows administrators with Keymaster parameter privileges to inject malicious X...
Feb 3, 2026An XML External Entity (XXE) vulnerability in Cisco ISE and ISE-PIC allows authenticated administrators to read arbitrary files on the underlying oper...
Jan 7, 2026This vulnerability in Biopython's Bio.Entrez module allows XML External Entity (XXE) attacks through improper restriction of XML doctype declarations....
Dec 18, 2025This vulnerability allows attackers to perform XML External Entity (XXE) attacks against Hitachi Vantara Pentaho Business Analytics Server. By submitt...
Apr 16, 2025This CVE describes an XML External Entity (XXE) injection vulnerability that allows attackers to read arbitrary files from affected systems. It affect...
Mar 5, 2025This XXE vulnerability in Adobe ColdFusion allows high-privileged attackers to bypass security restrictions and access sensitive information without u...
Jul 8, 2025This vulnerability in Dell AppSync 4.6.0.0 allows a low-privileged attacker with local access to exploit an XML External Entity (XXE) flaw, potentiall...
Jul 21, 2025Agiloft Release 28 contains an XML External Entities (XXE) vulnerability in import/export functionality that allows authenticated attackers to perform...
Aug 26, 2025CVE-2025-66372 is an XML External Entity (XXE) vulnerability in Mustang library versions before 2.16.3 that allows attackers to exfiltrate files from ...
Nov 28, 2025This CVE describes an XML External Entity (XXE) vulnerability in Asterisk's XML parsing function. It allows attackers to read sensitive files from the...
Feb 6, 2026This XXE vulnerability in Schneider Electric's EBO system allows attackers to read local files, interact with internal systems, or cause denial of ser...
Feb 11, 2026About CWE-611 (CWE-611)
Our database tracks 249 CVEs classified as CWE-611, with 72 rated critical and 141 rated high severity. The average CVSS score for CWE-611 vulnerabilities is 7.9.
External reference: View CWE-611 on MITRE CWE →
Monitor CWE-611 Vulnerabilities
Get alerted when new CWE-611 CVEs affect your infrastructure.
Start Monitoring Free