XML External Entity Reference

CWE-611 · 12 records · 6 with a public proof-of-concept

Records the NVD classes as XML External Entity Reference (CWE-611), highest CVSS first.

  1. CRITICAL 9.3CVE-2026-61741public PoC

    http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. Prior to versions 0.24.1 and 1.0.0-M39, these decoders used a `javax.xml.parsers.SAXParserFactory` obtained from `SAXParserFactory.newInstance` without any se…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 8.5CVE-2026-17646

    IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper restriction of XML external entity references.

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 8.2CVE-2026-10025

    IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). Wh…

    qradar security information and event manager

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 7.7CVE-2026-82386public PoC

    Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a weblog administrator to read files readable by the Roller process and reach internal network addresses by importing a crafted OPML document, because the bookmark import parse…

    AI risk analysis on Exploit-DB.ai →

  5. HIGH 7.7CVE-2026-82376public PoC

    Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a user with entry-editing rights on a weblog to cause the server to parse an attacker-influenced trackback response with an XML parser that does not disable external entity res…

    AI risk analysis on Exploit-DB.ai →

  6. HIGH 7.7CVE-2026-81536

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.

    AI risk analysis on Exploit-DB.ai →

  7. HIGH 7.5CVE-2026-61570public PoC

    MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 5.5.5 until 16.4.1, MerlinReader creates a DocumentBuilder with default settings while parsing XML from the ZTIMEINTERVALS column of a Merlin proj…

    AI risk analysis on Exploit-DB.ai →

  8. HIGH 7.4CVE-2026-18184

    IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw.

    AI risk analysis on Exploit-DB.ai →

  9. HIGH 7.4CVE-2026-18172

    IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper restriction of XML external entity references.

    AI risk analysis on Exploit-DB.ai →

  10. MEDIUM 6.5CVE-2026-93030

    FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity injection flaw.

    AI risk analysis on Exploit-DB.ai →

  11. MEDIUM 6.5CVE-2026-94108public PoC

    getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array helper function that fails to properly disable entity loading on PHP before 8.0. Attackers can craft malicious XML metadata in media files to disclose local files, p…

    AI risk analysis on Exploit-DB.ai →

  12. MEDIUM 5.5CVE-2026-14304public PoC

    In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. I…

    accessibility tools framework · michecker

    AI risk analysis on Exploit-DB.ai →