Threats Tagged 'cwe-611'
View all threats tagged with 'cwe-611'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-611'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-15803: CWE-611 in Eclipse Foundation Eclipse RDF4JCVE-2026-15803 0 Eclipse RDF4J contains an XML External Entity (XXE) vulnerability due to incomplete restrictions on XML parser entry points. This allows processing of DOCTYPE declarations, external entity references, and external DTD loading when parsing untrusted XML-based RDF data or query results. The issue stems from an incomplete fix for a prior vulnerability (CVE-2018-1000644). The vulnerability is addressed in version 5.3.2 by disabling these XML features by default. Join the discussion | CVE Database V5 | 08/12/2026, 15:38:30 UTC Added: 08/12/2026, 16:12:47 UTC |
CVE-2026-16999: CWE-611 Improper restriction of XML external entity reference in Ministry of Justice UYAP Document EditorCVE-2026-16999 0 CVE-2026-16999 is an XML External Entity (XXE) vulnerability in the Ministry of Justice UYAP Document Editor. It affects version 4.5.17 and allows improper restriction of XML external entity references, leading to serialized data external linking. The vulnerability has a medium severity with a CVSS score of 6.3. No official patch or remediation guidance is currently available from the vendor. There are no known exploits in the wild at this time. Join the discussion | CVE Database V5 | 08/12/2026, 13:53:18 UTC Added: 08/12/2026, 13:56:56 UTC |
CVE-2026-58248: CWE-611: Improper Restriction of XML External Entity Reference in SAP_SE SAP BusinessObjects Business IntelligenceCVE-2026-58248 0 SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a specially crafted spreadsheet file containing malicious external references. When the file is processed as a data source, the affected component resolves these references and exposes the contents of sensitive server-side files within the resulting report. This results in a high impact on confidentiality, with no impact on integrity and availability. Join the discussion | CVE Database V5 | 08/11/2026, 00:17:16 UTC Added: 08/11/2026, 00:42:04 UTC |
CVE-2026-16626: CWE-611 Improper restriction of XML external entity reference in Jaspersoft JasperReports ServerCVE-2026-16626 0 Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server. This issue affects JasperReports Server: from 9.0.0 before HF-9 and from 10.0.0 before HF-10. Join the discussion | CVE Database V5 | 08/10/2026, 18:00:20 UTC Added: 08/10/2026, 18:12:20 UTC |
CVE-2026-65432: CWE-611 Improper Restriction of XML External Entity Reference in Apache Software Foundation Apache CXFCVE-2026-65432 0 Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any <wsdl:import> or <xsd:import> referenced from that top-level WSDL is handed off to WSDL4J, which does not disable DOCTYPE declarations or external entities. As a result, the protections applied to the top-level document do not extend to imported documents, leaving imported WSDL/XSD content vulnerable to XML External Entity (XXE) attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue. Join the discussion | CVE Database V5 | 08/06/2026, 10:26:12 UTC Added: 08/06/2026, 11:12:04 UTC |
CVE-2026-10025: CWE-611 Improper Restriction of XML External Entity Reference in IBM QRadarCVE-2026-10025 0 IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to port 514 (UDP/TCP) without authentication. Join the discussion | CVE Database V5 | 08/05/2026, 16:03:19 UTC Added: 08/05/2026, 16:11:52 UTC |
CVE-2026-14304: CWE-611 in Eclipse Foundation Eclipse Accessibility Tools Framework (ACTF)CVE-2026-14304 0 An XML External Entity (XXE) vulnerability (CWE-611) exists in Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0, including source versions up to v20260630 and miChecker up to 3.1.0. Exploitation could allow a malicious actor to access local or internal network resources on systems running affected applications. The vulnerability has a medium severity with a CVSS 4.6 score. No official patch or remediation guidance has been provided yet. Join the discussion | CVE Database V5 | 08/05/2026, 10:40:03 UTC Added: 08/05/2026, 11:11:59 UTC |
CVE-2025-36374: CWE-611 Improper Restriction of XML External Entity Reference in IBM DataPower Gateway 10.6CDCVE-2025-36374 0 IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources. Join the discussion | CVE Database V5 | 07/30/2026, 17:55:11 UTC Added: 07/30/2026, 18:23:20 UTC |
CVE-2026-54082: CWE-611: Improper Restriction of XML External Entity Reference in veraPDF veraPDF-validationCVE-2026-54082 0 veraPDF-validation versions from 1.25.73 up to but not including 1.30.2, and versions before 1.31.71, contain an XML External Entity (XXE) vulnerability. This vulnerability exists in the PDFAValidator.validate(...) and GFPDAcroForm.getdynamicRender() functions, where XML parsing of rich-text annotations, form-field values, and XFA configurations in untrusted PDFs can lead to local file disclosure and outbound network requests. The issue is fixed in versions 1.30.2 and 1.31.71. Join the discussion | CVE Database V5 | 07/29/2026, 15:14:19 UTC Added: 07/29/2026, 15:37:56 UTC |
CVE-2026-54079: CWE-611: Improper Restriction of XML External Entity Reference in veraPDF veraPDF-validationCVE-2026-54079 0 veraPDF validation provides PDF/A and PDF/UA validation, feature reporting, and metadata repair. From 1.17.35 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity (XXE) vulnerability in validation-model/src/main/java/org/verapdf/gf/model/impl/pd/GFPDAcroForm.java in the getdynamicRender() method, where a crafted PDF containing a malicious XFA stream can cause external entity expansion during PDF/UA-1 validation and allow local file disclosure or outbound server-side requests. This issue is fixed in versions 1.30.2 and 1.31.71. Join the discussion | CVE Database V5 | 07/29/2026, 15:07:23 UTC Added: 07/29/2026, 15:37:56 UTC |
Showing 1 to 10 of 14 results