CWE-611: Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
491 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-58360 — GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
- CVE-2025-2775 — SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection
- CVE-2024-34102 — XXE can expose crypt key and other secrets granting full admin access
- CVE-2025-11700 — N-central Multiple XXE Injection Vulnerabilities
- CVE-2025-2777 — SysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injection
- CVE-2025-30220 — GeoTools, GeoServer, and GeoNetwork XML External Entity (XXE) Processing Vulnerability in XSD schema handling
- CVE-2026-32251 — Tolgee has an XXE Injection in Translation Import
- CVE-2025-49535 — ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
- CVE-2025-4641 — XML External Entity (XXE) injection vulnerability in WebDriverManager
- CVE-2024-34711 — GeoServer has improper ENTITY_RESOLUTION_ALLOWLIST URI validation in XML Processing (SSRF)
- CVE-2025-31039 — WordPress Category Icon plugin <= 1.0.2 - XML External Entity (XXE) vulnerability
- CVE-2025-2905 — An XML External Entity (XXE) vulnerability in Multiple WSO2 Products
- CVE-2025-10183 — XML External Entity Injection in TecConnect 4.1
- CVE-2025-48006 — Improper restriction of XML external entity reference issue exists in DataSpider Servista 4.4 and earlier. If a speciall
- CVE-2025-4639 — Improper Restriction of XML External Entity Reference in Peergos
- CVE-2025-36049 — IBM webMethods Integration Sever XML external entity injection
- CVE-2024-52596 — SimpleSAMLphp xml-common XXE vulnerability
- CVE-2025-48882 — PHPOffice Math allows XXE when processing an XML file in the MathML format
- CVE-2025-27523 — XXE vulnerability in JP1/IT Desktop Management 2 - Smart Device Manager
- CVE-2026-3511 — Improper Restriction of XML External Entity Reference vulnerability in XMLUtils.java in Slovensko.Digital Autogram allow
Recently published
- CVE-2026-19596 — OpenNMS XML collector XXE allows arbitrary file read from the OpenNMS host
- CVE-2026-19614 — XML External Entity (XXE) Injection in CyberELF NanoXML
- CVE-2026-71375 — XXE Vulnerability in Cosminexus Component Container
- CVE-2026-76958 — XML External Entity (XXE) Vulnerability in SAP Integration Suite
- CVE-2026-17443 — IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs
- CVE-2026-17444 — IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs
- CVE-2026-81832 — IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs
- CVE-2026-82525 — Exterro FTK Imager < 8.3 XXE via Report.xml XSLT Processing
- CVE-2026-82918 — XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporation improperly restrict XML external entity refere
- CVE-2026-17615 — Resteasy-core: resteasy sourceprovider remote unauthenticated file read
- CVE-2026-82880 — YaCy Search Server through 1.941 XML External Entity Injection via Parsers
- CVE-2026-55848 — mapfish-print: XXE on MapFish Print allows reading arbitrary files of certain types
- CVE-2026-76572 — pkp pkp-lib XSLTransformer.php _transformPHP xml external entity reference
- CVE-2026-20320 — A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote
- CVE-2026-67268 — Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vul
- CVE-2026-70423 — Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML External Entity Reference v
- CVE-2026-75058 — In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers
- CVE-2026-75055 — In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE
- CVE-2026-69101 — Datavane TIS v5.0.0 XXE Injection via doEditWorkflow Endpoint
- CVE-2026-18715 — IBM i is Affected By Multiple Vulnerabilities in WebSphere Application Server Liberty