Skip to main content

CWE archive

CWE-611 CVEs

Programmatic archive

1,270 CVEs tagged with CWE-611259 Critical, 567 High, 410 Medium, 34 Low, 0 Unrated.

CVE-2025-12531

Published Nov 3, 2025

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploi…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64134

Published Oct 29, 2025

Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure its XML parser to prevent XML external entity (XXE) attacks.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-46425

Published Oct 24, 2025

Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with r…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-6985

Published Oct 6, 2025

The HTMLSectionSplitter class in langchain-text-splitters version 0.3.8 is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing. This vulnerability arises be…

CVSS 7.5 · High

CVE-2025-11341

Published Oct 6, 2025

A security flaw has been discovered in Jinher OA up to 2.0. This affects an unknown function of the file /c6/Jhsoft.Web.module/eformaspx/WebDesign.aspx/?type=SystemUserInfo&style=…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48006

Published Sep 29, 2025

Improper restriction of XML external entity reference issue exists in DataSpider Servista 4.4 and earlier. If a specially crafted request is processed, arbitrary files on the file…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-11140

Published Sep 29, 2025

A vulnerability was identified in Bjskzy Zhiyou ERP up to 11.0. Affected by this vulnerability is the function openForm of the component com.artery.richclient.RichClientService. S…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-11035

Published Sep 26, 2025

A vulnerability was determined in Jinher OA 2.0. The impacted element is an unknown function of the file /c6/Jhsoft.Web.module/ToolBar/ManageWord.aspx/?text=GetUrl&style=1. This m…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-10816

Published Sep 22, 2025

A security flaw has been discovered in Jinher OA 2.0. This affects an unknown part of the file /c6/Jhsoft.Web.module/ToolBar/GetWordFileName.aspx/?text=GetUrl&style=add of the com…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-10183

Published Sep 9, 2025

A blind XML External Entity (XXE) injection in the OpenMessaging webservice in TecCom TecConnect 4.1 allows an unauthenticated attacker to exfiltrate arbitrary files to an attacke…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2025-10092

Published Sep 8, 2025

A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown function of the file /c6/Jhsoft.Web.projectmanage/TaskManage/AddTask.aspx/?Type=add of the component XML…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-10091

Published Sep 8, 2025

A vulnerability has been found in Jinher OA up to 1.2. This affects an unknown function of the file /c6/Jhsoft.Web.projectmanage/ProjectManage/XmlHttp.aspx/?Type=add of the compon…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2023-7307

Published Aug 27, 2025

Sangfor Behavior Management System (also referred to as DC Management System in Chinese-language documentation) contains an XML external entity (XXE) injection vulnerability in th…

CVSS 8.7 · High

CVE-2025-35112

Published Aug 26, 2025

Agiloft Release 28 contains an XML External Entities vulnerability in any table that allows 'import/export', allowing an authenticated attacker to import the template file and per…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-57704

Published Aug 26, 2025

Delta Electronics EIP Builder version 1.11 is vulnerable to a File Parsing XML External Entity Processing Information Disclosure Vulnerability.

CVSS 5.5 · Medium

CVE-2025-54988

Published Aug 20, 2025

Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection…

CVSS 8.4 · High
evidence mentions
6
Buzz score
27.5
Vendor/product tagsBeta · best-effort

CVE-2025-4044

Published Aug 19, 2025

Improper Restriction of XML External Entity Reference in various Lexmark printer drivers for Windows allows attacker to disclose sensitive information to an arbitrary URL.

CVSS 8.2 · High

CVE-2025-26484

Published Aug 14, 2025

Dell CloudLink, versions 8.0 through 8.1.1, contains an Improper Restriction of XML External Entity Reference vulnerability. A high privileged attacker with remote access could po…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-40584

Published Aug 12, 2025

A vulnerability has been identified in SIMOTION SCOUT TIA V5.4 (All versions), SIMOTION SCOUT TIA V5.5 (All versions), SIMOTION SCOUT TIA V5.6 (All versions < V5.6 SP1 HF7), SIMOT…

CVSS 6.8 · Medium

CVE-2025-54992

Published Aug 11, 2025

OpenKilda is an open-source OpenFlow controller. Prior to version 1.164.0, an XML external entity (XXE) injection vulnerability was found in OpenKilda which in combination with GH…

CVSS 6.9 · Medium

CVE-2025-8355

Published Aug 8, 2025

In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML containing references to internal U…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-54254

Published Aug 5, 2025

Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary fi…

CVSS 8.6 · High
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2025-36608

Published Jul 30, 2025

Dell SmartFabric OS10 Software, versions prior to 10.6.0.5, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 101-125 of 1,270 CVEsPage 5 of 51