CVE-2026-19614
The API is prone to XML external entity (XXE) injection. By default, XML external entity support is enabled. This issue affects NanoXML: 2.2.3.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
- EPSS probability
- 0.23%
- CWE
- CWE-611
- Published
- 2026-09-08
- Last modified
- 2026-09-08
Affected products
- CyberELF NanoXML