Skip to main content

CWE archive

CWE-611 CVEs

Programmatic archive

1,270 CVEs tagged with CWE-611259 Critical, 567 High, 410 Medium, 34 Low, 0 Unrated.

CVE-2022-50899

Published Jan 13, 2026

Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in PDF rendering that allows attackers to retrieve arbitrary files from the server. Attackers can explo…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-68493

Published Jan 11, 2026

Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users a…

CVSS 8.1 · High
evidence mentions
5
Buzz score
32.4
Vendor/product tagsBeta · best-effort

CVE-2026-22186

Published Jan 7, 2026

Bio-Formats versions up to and including 8.3.0 contain an XML External Entity (XXE) vulnerability in the Leica Microsystems metadata parsing component (e.g., XLEF). The parser use…

CVSS 4.6 · Medium
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-20029

Published Jan 7, 2026

A vulnerability in the licensing features of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote atta…

CVSS 4.9 · Medium
evidence mentions
5
Buzz score
34.4

CVE-2025-68280

Published Jan 5, 2026

Improper Restriction of XML External Entity Reference vulnerability in Apache SIS. It is possible to write XML files in such a way that, when parsed by Apache SIS, an XML file…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-15251

Published Dec 30, 2025

A vulnerability was detected in beecue FastBee up to 2.1. Impacted is the function getRootElement of the file springboot/fastbee-server/sip-server/src/main/java/com/fastbee/sip/ha…

CVSS 6.3 · Medium

CVE-2019-25253

Published Dec 24, 2025

KYOCERA Net Admin 3.4.0906 contains an XML External Entity (XXE) injection vulnerability in the Multi-Set Template Editor that allows unauthenticated attackers to read arbitrary s…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-25142

Published Dec 24, 2025

NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft…

CVSS 7.1 · High

CVE-2024-58335

Published Dec 24, 2025

OpenXRechnungToolbox through 2024-10-05-3.0.0 before 6c50e89 allows XXE because the disallow-doctype-decl feature is not enabled in visualization/VisualizerImpl.java.

CVSS 5.0 · Medium

CVE-2025-68463

Published Dec 18, 2025

Bio.Entrez in Biopython through 186 allows doctype XXE.

CVSS 4.9 · Medium

CVE-2025-61823

Published Dec 10, 2025

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrar…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-61821

Published Dec 10, 2025

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrar…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-61813

Published Dec 10, 2025

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrar…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66516

Published Dec 4, 2025

Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML Exter…

CVSS 8.4 · High
evidence mentions
11
Buzz score
32.9
Vendor/product tagsBeta · best-effort

CVE-2025-65868

Published Dec 3, 2025

XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST request.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66372

Published Nov 28, 2025

Mustang before 2.16.3 allows exfiltrating files via XXE attacks.

CVSS 2.8 · Low

CVE-2025-66371

Published Nov 28, 2025

Peppol-py before 1.1.1 allows XXE attacks because of the Saxon configuration. When validating XML-based invoices, the XML parser could read files from the filesystem and expose th…

CVSS 5.0 · Medium

CVE-2025-66370

Published Nov 28, 2025

Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice in the ZUGFeRD format, it is possible to read and exfiltrate files from the server's filesystem.

CVSS 5.0 · Medium

CVE-2025-58360

Published Nov 25, 2025

GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XML External Entity (XXE) vulner…

CVSS 8.2 · High
evidence mentions
3
Buzz score
46.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2025-63917

Published Nov 17, 2025

PDFPatcher thru 1.1.3.4663 executable's XML bookmark import functionality does not restrict XML external entity (XXE) references. The application uses .NET's XmlDocument class wit…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-13209

Published Nov 15, 2025

A weakness has been identified in bestfeng oa_git_free up to 9.5. This affects the function updateWriteBack of the file yimioa-oa9.5\server\c-flow\src\main\java\com\cloudweb\oa\co…

CVSS 2.1 · Low

CVE-2025-11700

Published Nov 12, 2025

N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure

CVSS 8.4 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-64518

Published Nov 10, 2025

The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, validating, and parsing SBOMs. Starting in version 2.1.0 and prio…

CVSS 7.5 · High

CVE-2025-63551

Published Nov 6, 2025

A Server-Side Request Forgery (SSRF) vulnerability, achievable through an XML External Entity (XXE) injection, exists in MetInfo Content Management System (CMS) thru 8.1. This fla…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 76-100 of 1,270 CVEsPage 4 of 51