CWE-776: CWE-776

10
Total CVEs
2
Critical
5
High
7.4
Avg CVSS

Yearly Trend

2026
1
2025
2
2024
3
2023
1
2022
1

Top Affected Vendors

1 Netapp 2
2 Debian 2
3 Fedoraproject 1
4 Libexpat Project 1
5 Apache 1
6 Oracle 1
7 Canonical 1
8 Tryton 1
9 Apereo 1
10 Typecho 1

All CWE-776 CVEs (10)

CVE-2019-19144
9.8

This CVE describes an XML External Entity (XXE) injection vulnerability in Quantum DXi6702 backup appliances. Attackers can exploit this via the REST ...

Aug 1, 2025
CVE-2021-23926
9.1

This vulnerability in XMLBeans XML parsers allows attackers to perform XML Entity Expansion (XXE) attacks by submitting malicious XML input. It affect...

Jan 14, 2021
CVE-2021-32623
8.1

CVE-2021-32623 is a billion laughs attack vulnerability in Opencast that allows authenticated users with ingest privileges to execute a permanent deni...

Jun 16, 2021
CVE-2026-29074
7.5

SVGO versions 2.1.0-2.8.0, 3.0.0-3.3.2, and before 4.0.1 are vulnerable to XML entity expansion attacks. Attackers can craft small malicious SVG files...

Mar 6, 2026
CVE-2024-28757
7.5

CVE-2024-28757 is an XML Entity Expansion vulnerability in libexpat that allows attackers to cause denial of service through resource exhaustion when ...

Mar 10, 2024
CVE-2023-49967
7.5

Typecho v1.2.1 is vulnerable to an XML Quadratic Blowup attack through its XML-RPC endpoint at /index.php/action/xmlrpc. This allows attackers to caus...

Dec 7, 2023
CVE-2022-26662
7.5

This CVE describes an XML Entity Expansion (XEE) vulnerability in Tryton Application Platform that allows unauthenticated attackers to send crafted XM...

Mar 10, 2022
CVE-2025-0617
5.9

This XML entity expansion vulnerability in HX 10.0.0 and earlier allows attackers to cause denial of service by sending specially crafted data to the ...

Jan 29, 2025
CVE-2024-27142
5.9

This vulnerability affects Toshiba printers that use XML communication for their API endpoint. Attackers can exploit a time-based blind XML External E...

Jun 14, 2024
CVE-2022-28652
5.5

This vulnerability in Apport's settings file parsing allows a billion laughs attack (XML entity expansion) that can cause denial of service through ex...

Jun 4, 2024

About CWE-776 (CWE-776)

Our database tracks 10 CVEs classified as CWE-776, with 2 rated critical and 5 rated high severity. The average CVSS score for CWE-776 vulnerabilities is 7.4.

External reference: View CWE-776 on MITRE CWE →

Monitor CWE-776 Vulnerabilities

Get alerted when new CWE-776 CVEs affect your infrastructure.

Start Monitoring Free