Skip to main content

CWE archive

CWE-611 CVEs

Programmatic archive

1,287 CVEs tagged with CWE-611260 Critical, 575 High, 418 Medium, 34 Low, 0 Unrated.

CVE-2025-53621

Published Jul 15, 2025

DSpace open source software is a repository application which provides durable access to digital resources. Two related XML External Entity (XXE) injection possibilities impact al…

CVSS 6.9 · Medium
evidence mentions
7
Buzz score
25.8

CVE-2025-53689

Published Jul 14, 2025

Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are re…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-7523

Published Jul 13, 2025

A vulnerability was found in Jinher OA 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /c6/Jhsoft.Web.message/ToolBar/DelTemp.a…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-6438

Published Jul 11, 2025

A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause manipulation of SOAP API calls and XML external entities injection re…

CVSS 5.9 · Medium

CVE-2025-49544

Published Jul 8, 2025

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in a Secu…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-49539

Published Jul 8, 2025

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in a secu…

CVSS 4.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-49535

Published Jul 8, 2025

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in a Secu…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-49493

Published Jun 30, 2025

Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.

CVSS 5.8 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2025-52888

Published Jun 24, 2025

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. A critical XML External Entity (XXE) vulnerability exists in the xunit-xml-plugin used b…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0

CVE-2025-47293

Published Jun 19, 2025

PowSyBl (Power System Blocks) is a framework to build power system oriented software. Prior to version 6.7.2, in certain places, powsybl-core XML parsing is vulnerable to an XML e…

CVSS 2.7 · Low
evidence mentions
3
Buzz score
18.9

CVE-2025-44044

Published Jun 10, 2025

Keyoti SearchUnit prior to 9.0.0. is vulnerable to XML External Entity (XXE). An attacker who can force a vulnerable SearchUnit host into parsing maliciously crafted XML and/or DT…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2024-34711

Published Jun 10, 2025

GeoServer is an open source server that allows users to share and edit geospatial data. An improper URI validation vulnerability exists that enables an unauthorized attacker to pe…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-31039

Published Jun 9, 2025

Improper Restriction of XML External Entity Reference vulnerability in pixelgrade Category Icon category-icon allows XML Entity Linking.This issue affects Category Icon: from n/a…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2025-5877

Published Jun 9, 2025

A vulnerability, which was classified as problematic, has been found in Fengoffice Feng Office 3.2.2.1. Affected by this issue is some unknown functionality of the file /applicati…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2025-48882

Published May 30, 2025

PHPOffice Math is a library that provides a set of classes to manipulate different formula file formats. Prior to version 0.3.0, loading XML data using the standard `libxml` exten…

CVSS 8.7 · High
evidence mentions
2
Buzz score
16.0

CVE-2025-4338

Published May 22, 2025

Lantronix Device installer is vulnerable to XML external entity (XXE) attacks in configuration files read from the network device. An attacker could obtain credentials, access the…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-4949

Published May 21, 2025

In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git t…

CVSS 6.8 · Medium
evidence mentions
7
Buzz score
30.8
Vendor/product tagsBeta · best-effort

CVE-2025-27523

Published May 15, 2025

XXE vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Device Manager: from 12-00 before…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-4641

Published May 14, 2025

Improper Restriction of XML External Entity Reference vulnerability in bonigarcia webdrivermanager WebDriverManager on Windows, MacOS, Linux (XML parsing components modules) allow…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2025-4639

Published May 14, 2025

CWE-611 Improper Restriction of XML External Entity Reference in the getDocumentBuilder() method of WebDav servlet in Peergos. This issue affects Peergos through version 1.1.0.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-47778

Published May 14, 2025

Sulu is an open-source PHP content management system based on the Symfony framework. Starting in versions 2.5.21, 2.6.5, and 3.0.0-alpha1, an admin user can upload SVG which may l…

CVSS 6.1 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2024-51445

Published May 13, 2025

A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The affected application contains a XML External Entity Injection (X…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort
Showing 151-175 of 1,287 CVEsPage 7 of 52