<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – XML External Entity (XXE)</title>
  <link>https://cvedaily.com/pages/tags/xxe.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/xxe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – XML External Entity (XXE)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:38 +0000</lastBuildDate>
  <item>
    <title>[Low] CVE-2026-49383 – In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49383</guid>
    <pubDate>Fri, 29 May 2026 19:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-49383</strong></p>
  <p>In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3603 – IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through  Interim Fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3603</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3603</guid>
    <pubDate>Tue, 26 May 2026 19:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3603</strong></p>
  <p>IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through  Interim Fix 021, 7.1.0  Interim Fix 001 through  Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3603">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44618 – Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44618</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44618</guid>
    <pubDate>Fri, 22 May 2026 13:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44618</strong></p>
  <p>Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44618">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39053 – Oinone Pamirs 7.0.0 contains an XML External Entity (XXE) issue in its XStream-b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39053</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39053</guid>
    <pubDate>Fri, 15 May 2026 15:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39053</strong></p>
  <p>Oinone Pamirs 7.0.0 contains an XML External Entity (XXE) issue in its XStream-based XML parsing logic. When attacker-controlled XML is passed to framework parsing entry points such as PamirsXmlUtils.fromXML(...) or ViewXmlUtils.fromXML(...), unsafe XML processing can lead to file disclosure or SSRF.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39053">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20224 – A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20224</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20224</guid>
    <pubDate>Thu, 14 May 2026 17:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20224</strong></p>
  <p>A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system. The attacker does not need to have valid user credentials.  This vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing an XML file. An attacker could exploit t…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20224">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44445 – ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44445</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44445</guid>
    <pubDate>Wed, 13 May 2026 22:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44445</strong></p>
  <p>ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.12.0, an improper restriction of XML external entity (XXE) reference vulnerability in the EDI Module enables an authenticated attacker to read files from the local file system, including sensitive configuration files. This vulnerability is fixed in 15.104.3 and 16.12.0.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44445">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31248 – Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31248</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31248</guid>
    <pubDate>Mon, 11 May 2026 17:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31248</strong></p>
  <p>Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend extracts and validates XML files from .tar.gz archives using etree.fromstring() without disabling entity resolution. An attacker can craft a malicious XML file with nested entity definitions (XML Bomb) and package it into a .tar.gz archive. When processed by Docling, the exponential expansion o…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-776</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31248">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31247 – Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31247</guid>
    <pubDate>Mon, 11 May 2026 16:17:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31247</strong></p>
  <p>Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend uses etree.parse() to parse XML files without disabling entity resolution. An attacker can craft a malicious XML file containing a nested entity expansion payload (XML Bomb). When processed by Docling, the exponential expansion of entities leads to excessive resource consumption, resulting in a…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-42346 – Alkacon OpenCms before 16 allows XXE when the &lt;!DOCTYPE&gt; refers to an external h...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-42346</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-42346</guid>
    <pubDate>Fri, 08 May 2026 05:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-42346</strong></p>
  <p>Alkacon OpenCms before 16 allows XXE when the <!DOCTYPE> refers to an external host.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-42346">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-42344 – Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-42344</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-42344</guid>
    <pubDate>Fri, 08 May 2026 05:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-42344</strong></p>
  <p>Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/query XXE attack on a Chemistry servlet.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-42344">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41936 – Vvveb before version 1.0.8.2 contains an XML external entity (XXE) injection vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41936</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41936</guid>
    <pubDate>Wed, 06 May 2026 19:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41936</strong></p>
  <p>Vvveb before version 1.0.8.2 contains an XML external entity (XXE) injection vulnerability in the admin Tools/Import feature that allows authenticated site_admin users to read arbitrary files and modify database records. Attackers can exploit the XML parser configuration in system/import/xml.php to inject file:// or php://filter entity references that are resolved and persisted into the applicati…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41936">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-38429 – OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-38429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-38429</guid>
    <pubDate>Tue, 05 May 2026 17:17:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-38429</strong></p>
  <p>OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature due to insecure XML parsing of user supplied .zip files containing a manifest.xml.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-38429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40682 – XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP D...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40682</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40682</guid>
    <pubDate>Mon, 04 May 2026 17:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40682</strong></p>
  <p>XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor   Versions Affected: before 2.5.9, before 3.0.0-M3   Description: The DictionaryEntryPersistor class initializes a static SAXParserFactory at class-load time without enabling FEATURE_SECURE_PROCESSING or disabling DTD processing. When create(InputStream, EntryInserter) is invoked, the only feat…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40682">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6501 – Improper restriction of XML external entity reference vulnerability in ILM Infor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6501</guid>
    <pubDate>Mon, 04 May 2026 15:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6501</strong></p>
  <p>Improper restriction of XML external entity reference vulnerability in ILM Informatique jOpenDocument allows Data Serialization External Entities Blowup.  This issue affects jOpenDocument: 1.5.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-36765 – An XML external entity (XXE) vulnerability in the /designer/loadReport endpoint ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-36765</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-36765</guid>
    <pubDate>Thu, 30 Apr 2026 18:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-36765</strong></p>
  <p>An XML external entity (XXE) vulnerability in the /designer/loadReport endpoint of SpringBlade v4.8.0 allows authenticated attackers to execute arbitrary code via injecting a crafted payload.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-36765">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-14543 – Improper Restriction of XML External Entity Reference vulnerability in Connext P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14543</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14543</guid>
    <pubDate>Thu, 30 Apr 2026 16:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-14543</strong></p>
  <p>Improper Restriction of XML External Entity Reference vulnerability in Connext Professional (Core Libraries) allows Serialized Data External Linking.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 4.3x before 5.2.*.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14543">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40882 – OpenRemote is an open-source internet-of-things platform. Prior to version 1.22...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40882</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40882</guid>
    <pubDate>Wed, 22 Apr 2026 21:17:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40882</strong></p>
  <p>OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.0, the Velbus asset import path parses attacker-controlled XML without explicit XXE hardening. An authenticated user who can call the import endpoint may trigger XML external entity processing, which can lead to server-side file disclosure and SSRF. The target file must be less than 1023 characters. Version 1.22.0 fix…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40882">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40042 – Pachno 1.0.6 contains an XML external entity injection vulnerability that allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40042</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40042</guid>
    <pubDate>Mon, 13 Apr 2026 19:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40042</strong></p>
  <p>Pachno 1.0.6 contains an XML external entity injection vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting unsafe XML parsing in the TextParser helper. Attackers can inject malicious XML entities through wiki table syntax and inline tags in issue descriptions, comments, and wiki articles to trigger entity resolution via simplexml_load_string() without LIBXML_…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-403</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40042">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33737 – Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, mu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33737</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33737</guid>
    <pubDate>Fri, 10 Apr 2026 19:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33737</strong></p>
  <p>Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, multiple files use simplexml_load_string() without XXE protection. With LIBXML_NOENT flag, arbitrary server files can be read. This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33737">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-4374 – Improper Restriction of XML External Entity Reference vulnerability in RTI Conne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4374</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4374</guid>
    <pubDate>Wed, 01 Apr 2026 02:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-4374</strong></p>
  <p>Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Routing Service,Observability Collector,Recording Service,Queueing Service,Cloud Discovery Service) allows Serialized Data External Linking, Data Serializat...</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4374">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29924 – Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29924</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29924</guid>
    <pubDate>Mon, 30 Mar 2026 19:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29924</strong></p>
  <p>Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the admin panel and File Manager plugin.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29924">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28809 – XML External Entity (XXE) vulnerability in esaml (and its forks) allows an attac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28809</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28809</guid>
    <pubDate>Mon, 23 Mar 2026 11:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28809</strong></p>
  <p>XML External Entity (XXE) vulnerability in esaml (and its forks) allows an attacker to cause the system to read local files and incorporate their contents into processed SAML documents, and potentially perform SSRF via crafted SAML messages.  esaml parses attacker-controlled SAML messages using xmerl_scan:string/2 before signature verification without disabling XML entity expansion. On Erlang/OTP…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28809">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33371 – An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. An XML Exte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33371</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33371</guid>
    <pubDate>Fri, 20 Mar 2026 14:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33371</strong></p>
  <p>An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. An XML External Entity (XXE) vulnerability exists in the Zimbra Exchange Web Services (EWS) SOAP interface due to improper handling of XML input. An authenticated attacker can submit crafted XML data that is processed by an XML parser with external entity resolution enabled. Successful exploitation may allow disclosure of sensit…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33371">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3511 – Improper Restriction of XML External Entity Reference vulnerability in XMLUtils...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3511</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3511</guid>
    <pubDate>Thu, 19 Mar 2026 12:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3511</strong></p>
  <p>Improper Restriction of XML External Entity Reference vulnerability in XMLUtils.java in Slovensko.Digital Autogram allows remote unauthenticated attacker to conduct SSRF (Server Side Request Forgery) attacks and obtain unauthorized access to local files on filesystems running the vulnerable application. Successful exploitation requires the victim to visit a specially crafted website that sends re…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3511">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28770 – Improper neutralization of special elements in the /IDC_Logging/checkifdone.cgi ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28770</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28770</guid>
    <pubDate>Wed, 04 Mar 2026 07:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28770</strong></p>
  <p>Improper neutralization of special elements in the /IDC_Logging/checkifdone.cgi script in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver Web management Interface version 101 allows for XML Injection. The application reflects un-sanitized user input from the `file` parameter directly into a CDATA block, allowing an authenticated attacker to break out of the tag…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28770">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1567 – IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 An XML External Enti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1567</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1567</guid>
    <pubDate>Tue, 03 Mar 2026 21:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1567</strong></p>
  <p>IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 An XML External Entity (XXE) vulnerability in IBM InfoSphere Information Server could allow attackers to retrieve sensitive information from the server.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1567">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3404 – A flaw has been found in thinkgem JeeSite up to 5.15.1. Impacted is an unknown f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3404</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3404</guid>
    <pubDate>Mon, 02 Mar 2026 02:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3404</strong></p>
  <p>A flaw has been found in thinkgem JeeSite up to 5.15.1. Impacted is an unknown function of the file /com/jeesite/common/shiro/cas/CasOutHandler.java of the component Endpoint. Executing a manipulation can lead to xml external entity reference. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is considered difficult. The exploit has been publis…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3404">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2252 – An XML External Entity (XXE) vulnerability allows malicious user to perform Serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2252</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2252</guid>
    <pubDate>Fri, 27 Feb 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2252</strong></p>
  <p>An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via crafted XML input containing malicious external entity references.  This issue affects Xerox FreeFlow Core versions up to and including 8.0.7.   Please consider upgrading to FreeFlow Core version 8.1.0 via the software available on -  https://www.support.xerox.com/en-us/product/core/…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2252">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36247 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36247</guid>
    <pubDate>Tue, 17 Feb 2026 18:20:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36247</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2536 – A vulnerability was determined in opencc JFlow up to 20260129. This affects the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2536</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2536</guid>
    <pubDate>Mon, 16 Feb 2026 06:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2536</strong></p>
  <p>A vulnerability was determined in opencc JFlow up to 20260129. This affects the function Imp_Done of the file src/main/java/bp/wf/httphandler/WF_Admin_AttrFlow.java of the component Workflow Engine. This manipulation of the argument File causes xml external entity reference. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2536">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-37192 – MSN Password Recovery 1.30 contains an XML external entity injection vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37192</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37192</guid>
    <pubDate>Wed, 11 Feb 2026 21:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-37192</strong></p>
  <p>MSN Password Recovery 1.30 contains an XML external entity injection vulnerability that allows attackers to read local system files through crafted XML input. Attackers can exploit the 'Favorites' tab by injecting a malicious XML file that references external entities to retrieve sensitive system configuration information.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37192">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1227 – CWE-611: Improper Restriction of XML External Entity Reference vulnerability exi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1227</guid>
    <pubDate>Wed, 11 Feb 2026 14:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1227</strong></p>
  <p>CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized disclosure of local files, interaction within the EBO system, or denial of service conditions when a local user uploads a specially crafted TGML graphics file to the EBO server from Workstation.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2074 – A vulnerability was identified in O2OA up to 9.0.0. This impacts an unknown func...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2074</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2074</guid>
    <pubDate>Sat, 07 Feb 2026 05:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2074</strong></p>
  <p>A vulnerability was identified in O2OA up to 9.0.0. This impacts an unknown function of the file /x_program_center/jaxrs/mpweixin/check of the component HTTP POST Request Handler. The manipulation leads to xml external entity reference. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2074">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-23739 – Asterisk is an open source private branch exchange and telephony toolkit. Prior ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23739</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23739</guid>
    <pubDate>Fri, 06 Feb 2026 17:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-23739</strong></p>
  <p>Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the ast_xml_open() function in xml.c parses XML documents using libxml with unsafe parsing options that enable entity expansion and XInclude processing. Specifically, it invokes xmlReadFile() with the XML_PARSE_NOENT flag and later processes XIncludes via x…</p>
  <p><strong>CVSS:</strong> 2.0 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23739">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-23795 – Improper Restriction of XML External Entity Reference vulnerability in Apache Sy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23795</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23795</guid>
    <pubDate>Tue, 03 Feb 2026 16:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-23795</strong></p>
  <p>Improper Restriction of XML External Entity Reference vulnerability in Apache Syncope Console. An administrator with adequate entitlements to create or edit Keymaster parameters via Console can construct malicious XML text to launch an XXE attack, thereby causing sensitive data leakage occurs.  This issue affects Apache Syncope: from 3.0 through 3.0.15, from 4.0 through 4.0.3.  Users are recommen…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23795">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13096 – IBM Business Automation Workflow containers V25.0.0 through V25.0.0-IF007, V24.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13096</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13096</guid>
    <pubDate>Mon, 02 Feb 2026 23:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13096</strong></p>
  <p>IBM Business Automation Workflow containers V25.0.0 through V25.0.0-IF007, V24.0.1 - V24.0.1-IF007, V24.0.0 - V24.0.0-IF007 and IBM Business Automation Workflow traditional V25.0.0, V24.0.1, V24.0.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13096">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21569 – This High severity XXE (XML External Entity Injection) vulnerability was introdu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21569</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21569</guid>
    <pubDate>Wed, 28 Jan 2026 01:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21569</strong></p>
  <p>This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 7.1.0 of Crowd Data Center and Server.  	 	This XXE (XML External Entity Injection) vulnerability, with a CVSS Score of 7.9, allows an authenticated attacker to access local and remote content which has high impact to confidentiality, low impact to integrity, high impact to availability, and requires no…</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21569">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-24400 – AssertJ provides Fluent testing assertions for Java and the Java Virtual Machine...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24400</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24400</guid>
    <pubDate>Mon, 26 Jan 2026 23:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-24400</strong></p>
  <p>AssertJ provides Fluent testing assertions for Java and the Java Virtual Machine (JVM). Starting in version 1.4.0 and prior to version 3.27.7, an XML External Entity (XXE) vulnerability exists in `org.assertj.core.util.xml.XmlStringPrettyFormatter`: the `toXmlDocument(String)` method initializes `DocumentBuilderFactory` with default settings, without disabling DTDs or external entities. This form…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24400">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-65482 – An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65482</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65482</guid>
    <pubDate>Tue, 20 Jan 2026 16:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-65482</strong></p>
  <p>An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitrary code via uploading a crafted .docx file.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65482">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1218 – A vulnerability was detected in Bjskzy Zhiyou ERP up to 11.0. Impacted is the fu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1218</guid>
    <pubDate>Tue, 20 Jan 2026 06:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1218</strong></p>
  <p>A vulnerability was detected in Bjskzy Zhiyou ERP up to 11.0. Impacted is the function initRCForm of the file RichClientService.class of the component com.artery.richclient.RichClientService. Performing a manipulation results in xml external entity reference. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this dis…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14478 – The Demo Importer Plus plugin for WordPress is vulnerable to XML External Entity...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14478</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14478</guid>
    <pubDate>Sat, 17 Jan 2026 08:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14478</strong></p>
  <p>The Demo Importer Plus plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in all versions up to, and including, 2.0.9 via the SVG file upload functionality. This makes it possible for authenticated attackers, with Author-level access and above, to achieve code execution in vulnerable configurations. This only impacts sites on versions of PHP older than 8.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14478">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-50899 – Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-50899</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-50899</guid>
    <pubDate>Tue, 13 Jan 2026 23:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-50899</strong></p>
  <p>Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in PDF rendering that allows attackers to retrieve arbitrary files from the server. Attackers can exploit the insecure XML parser by crafting a malicious XML document with external entity references to read system files through the baseURL parameter in PDF creation requests.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-50899">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22186 – Bio-Formats versions up to and including 8.3.0 contain an XML External Entity (X...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22186</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22186</guid>
    <pubDate>Wed, 07 Jan 2026 21:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22186</strong></p>
  <p>Bio-Formats versions up to and including 8.3.0 contain an XML External Entity (XXE) vulnerability in the Leica Microsystems metadata parsing component (e.g., XLEF). The parser uses an insecurely configured DocumentBuilderFactory when processing Leica XML-based metadata files, allowing external entity expansion and external DTD loading. A crafted metadata file can trigger outbound network requests…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22186">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36589 – Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restrict...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36589</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36589</guid>
    <pubDate>Tue, 06 Jan 2026 17:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36589</strong></p>
  <p>Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to data and resources outside of the intended sphere of control.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36589">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-68280 – Improper Restriction of XML External Entity Reference vulnerability in Apache SI...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68280</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68280</guid>
    <pubDate>Mon, 05 Jan 2026 14:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-68280</strong></p>
  <p>Improper Restriction of XML External Entity Reference vulnerability in Apache SIS.    It is possible to write XML files in such a way that, when parsed by Apache SIS, an XML file reveals to the attacker the content of a local file on the server running Apache SIS. This vulnerability impacts the following SIS services:       *  Reading of GeoTIFF files having the GEO_METADATA tag defined by the De…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68280">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-15251 – A vulnerability was detected in beecue FastBee up to 2.1. Impacted is the functi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15251</guid>
    <pubDate>Tue, 30 Dec 2025 14:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-15251</strong></p>
  <p>A vulnerability was detected in beecue FastBee up to 2.1. Impacted is the function getRootElement of the file springboot/fastbee-server/sip-server/src/main/java/com/fastbee/sip/handler/req/ReqAbstractHandler.java of the component SIP Message Handler. The manipulation results in xml external entity reference. It is possible to launch the attack remotely. A high complexity level is associated with…</p>
  <p><strong>CVSS:</strong> 5.6 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25253 – KYOCERA Net Admin 3.4.0906 contains an XML External Entity (XXE) injection vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25253</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25253</guid>
    <pubDate>Wed, 24 Dec 2025 20:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25253</strong></p>
  <p>KYOCERA Net Admin 3.4.0906 contains an XML External Entity (XXE) injection vulnerability in the Multi-Set Template Editor that allows unauthenticated attackers to read arbitrary system files. Attackers can craft a malicious XML file with external entity references to retrieve sensitive configuration data like database credentials through an out-of-band channel attack.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25253">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-25142 – NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML Ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25142</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25142</guid>
    <pubDate>Wed, 24 Dec 2025 20:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-25142</strong></p>
  <p>NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an out-of-band channel attack.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25142">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-58335 – OpenXRechnungToolbox through 2024-10-05-3.0.0 before 6c50e89 allows XXE because ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-58335</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-58335</guid>
    <pubDate>Wed, 24 Dec 2025 06:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-58335</strong></p>
  <p>OpenXRechnungToolbox through 2024-10-05-3.0.0 before 6c50e89 allows XXE because the disallow-doctype-decl feature is not enabled in visualization/VisualizerImpl.java.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-58335">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-68463 – Bio.Entrez in Biopython through 186 allows doctype XXE.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68463</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68463</guid>
    <pubDate>Thu, 18 Dec 2025 06:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-68463</strong></p>
  <p>Bio.Entrez in Biopython through 186 allows doctype XXE.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68463">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-61823 – ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61823</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61823</guid>
    <pubDate>Wed, 10 Dec 2025 00:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-61823</strong></p>
  <p>ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. A high privileged attacker could exploit this vulnerability to access sensitive files and data on the server. Exploitation of this issue requires user interaction and scope is changed.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61823">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-61821 – ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61821</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61821</guid>
    <pubDate>Wed, 10 Dec 2025 00:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-61821</strong></p>
  <p>ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and data on the server. Exploitation of this issue does not require user interaction and scope is changed.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61821">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61813 – ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61813</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61813</guid>
    <pubDate>Wed, 10 Dec 2025 00:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61813</strong></p>
  <p>ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the server. Exploitation of this issue does requires user interaction and scope is changed.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61813">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-66516 – Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66516</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66516</guid>
    <pubDate>Thu, 04 Dec 2025 17:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-66516</strong></p>
  <p>Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF.   This CVE covers the same vulnerability as in CVE-2025-54988. However, this CVE expands the scope of affected packages in two ways.   First, while the entrypo…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66516">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-65868 – XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65868</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65868</guid>
    <pubDate>Wed, 03 Dec 2025 21:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-65868</strong></p>
  <p>XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65868">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-66372 – Mustang before 2.16.3 allows exfiltrating files via XXE attacks.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66372</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66372</guid>
    <pubDate>Fri, 28 Nov 2025 04:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-66372</strong></p>
  <p>Mustang before 2.16.3 allows exfiltrating files via XXE attacks.</p>
  <p><strong>CVSS:</strong> 2.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66372">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-66371 – Peppol-py before 1.1.1 allows XXE attacks because of the Saxon configuration. Wh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66371</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66371</guid>
    <pubDate>Fri, 28 Nov 2025 04:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-66371</strong></p>
  <p>Peppol-py before 1.1.1 allows XXE attacks because of the Saxon configuration. When validating XML-based invoices, the XML parser could read files from the filesystem and expose their content to a remote host.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66371">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-66370 – Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66370</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66370</guid>
    <pubDate>Fri, 28 Nov 2025 04:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-66370</strong></p>
  <p>Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice in the ZUGFeRD format, it is possible to read and exfiltrate files from the server's filesystem.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66370">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58360 – GeoServer is an open source server that allows users to share and edit geospatia...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58360</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58360</guid>
    <pubDate>Tue, 25 Nov 2025 21:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58360</strong></p>
  <p>GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XML External Entity (XXE) vulnerability was identified. The application accepts XML input through a specific endpoint /geoserver/wms operation GetMap. However, this input is not sufficiently sanitized or restricted, allowing an attacker to define exter…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58360">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-63917 – PDFPatcher thru 1.1.3.4663 executable's XML bookmark import functionality does n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-63917</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-63917</guid>
    <pubDate>Mon, 17 Nov 2025 17:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-63917</strong></p>
  <p>PDFPatcher thru 1.1.3.4663 executable's XML bookmark import functionality does not restrict XML external entity (XXE) references. The application uses .NET's XmlDocument class without disabling external entity resolution, enabling attackers to: Read arbitrary files from the victim's filesystem, exfiltrate sensitive data via out-of-band (OOB) HTTP requests, perform SSRF attacks against internal ne…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-63917">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13209 – A weakness has been identified in bestfeng oa_git_free up to 9.5. This affects t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13209</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13209</guid>
    <pubDate>Sat, 15 Nov 2025 19:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13209</strong></p>
  <p>A weakness has been identified in bestfeng oa_git_free up to 9.5. This affects the function updateWriteBack of the file yimioa-oa9.5\server\c-flow\src\main\java\com\cloudweb\oa\controller\WorkflowPredefineController.java. This manipulation of the argument writeProp causes xml external entity reference. The attack is possible to be carried out remotely. The exploit has been made available to the p…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13209">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-64518 – The CycloneDX core module provides a model representation of the SBOM along with...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64518</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64518</guid>
    <pubDate>Mon, 10 Nov 2025 22:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-64518</strong></p>
  <p>The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, validating, and parsing SBOMs. Starting in version 2.1.0 and prior to version 11.0.1, the XML `Validator` used by cyclonedx-core-java was not configured securely, making the library vulnerable to XML External Entity (XXE) injection. The fix for GHSA-683x-4444-jxh8 / CVE-2024-38374 was…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64518">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-63551 – A Server-Side Request Forgery (SSRF) vulnerability, achievable through an XML Ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-63551</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-63551</guid>
    <pubDate>Thu, 06 Nov 2025 19:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-63551</strong></p>
  <p>A Server-Side Request Forgery (SSRF) vulnerability, achievable through an XML External Entity (XXE) injection, exists in MetInfo Content Management System (CMS) thru 8.1. This flaw stems from a defect in the XML parsing logic, which allows an attacker to construct a malicious XML entity that forces the server to initiate an HTTP request to an arbitrary internal or external network address. Succes…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-63551">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-10713 – An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10713</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10713</guid>
    <pubDate>Wed, 05 Nov 2025 18:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-10713</strong></p>
  <p>An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML parser. The application parses user-supplied XML without applying sufficient restrictions, allowing resolution of external entities.  A successful attack could enable a remote, unauthenticated attacker to read sensitive files from the server's filesystem or perform denial-of-servic…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10713">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12531 – IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12531</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12531</guid>
    <pubDate>Mon, 03 Nov 2025 20:17:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12531</strong></p>
  <p>IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12531">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-64134 – Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64134</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64134</guid>
    <pubDate>Wed, 29 Oct 2025 14:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-64134</strong></p>
  <p>Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure its XML parser to prevent XML external entity (XXE) attacks.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64134">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-46425 – Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Im...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46425</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46425</guid>
    <pubDate>Fri, 24 Oct 2025 14:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-46425</strong></p>
  <p>Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46425">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-9066 – A security issue was discovered within FactoryTalk® ViewPoint, allowing unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9066</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9066</guid>
    <pubDate>Tue, 14 Oct 2025 13:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-9066</strong></p>
  <p>A security issue was discovered within FactoryTalk® ViewPoint, allowing unauthenticated attackers to achieve XXE. Certain SOAP requests can be abused to perform XXE, resulting in a temporary denial-of-service.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9066">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-60833 – An XML External Entity (XXE) vulnerability in the /mall/wxpay/pay component of u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-60833</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-60833</guid>
    <pubDate>Wed, 08 Oct 2025 14:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-60833</strong></p>
  <p>An XML External Entity (XXE) vulnerability in the /mall/wxpay/pay component of uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying crafted XML data.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-60833">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-6985 – The HTMLSectionSplitter class in langchain-text-splitters version 0.3.8 is vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6985</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6985</guid>
    <pubDate>Mon, 06 Oct 2025 18:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-6985</strong></p>
  <p>The HTMLSectionSplitter class in langchain-text-splitters version 0.3.8 is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing. This vulnerability arises because the class allows the use of arbitrary XSLT stylesheets, which are parsed using lxml.etree.parse() and lxml.etree.XSLT() without any hardening measures. In lxml versions up to 4.9.x, external entities are resolved b…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6985">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11341 – A security flaw has been discovered in Jinher OA up to 2.0. This affects an unkn...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11341</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11341</guid>
    <pubDate>Mon, 06 Oct 2025 17:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11341</strong></p>
  <p>A security flaw has been discovered in Jinher OA up to 2.0. This affects an unknown function of the file /c6/Jhsoft.Web.module/eformaspx/WebDesign.aspx/?type=SystemUserInfo&style=1. Performing manipulation results in xml external entity reference. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11341">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20369 – In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Pl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20369</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20369</guid>
    <pubDate>Wed, 01 Oct 2025 17:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20369</strong></p>
  <p>In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a low privilege user that does not hold the "admin" or "power" Splunk roles could perform an extensible markup language (XML) external entity (XXE) injection through the dashboard tab label field. The XXE injection has the potential to cause denial of…</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-776</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20369">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-48006 – Improper restriction of XML external entity reference issue exists in DataSpider...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48006</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48006</guid>
    <pubDate>Mon, 29 Sep 2025 08:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-48006</strong></p>
  <p>Improper restriction of XML external entity reference issue exists in DataSpider Servista 4.4 and earlier. If a specially crafted request is processed, arbitrary files on the file system where the server application for the product is installed may be read, or a denial-of-service (DoS) condition may occur.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48006">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11140 – A vulnerability was identified in Bjskzy Zhiyou ERP up to 11.0. Affected by this...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11140</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11140</guid>
    <pubDate>Mon, 29 Sep 2025 04:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11140</strong></p>
  <p>A vulnerability was identified in Bjskzy Zhiyou ERP up to 11.0. Affected by this vulnerability is the function openForm of the component com.artery.richclient.RichClientService. Such manipulation of the argument contentString leads to xml external entity reference. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this d…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11140">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-11035 – A vulnerability was determined in Jinher OA 2.0. The impacted element is an unkn...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11035</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11035</guid>
    <pubDate>Fri, 26 Sep 2025 19:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-11035</strong></p>
  <p>A vulnerability was determined in Jinher OA 2.0. The impacted element is an unknown function of the file /c6/Jhsoft.Web.module/ToolBar/ManageWord.aspx/?text=GetUrl&style=1. This manipulation causes xml external entity reference. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11035">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10816 – A security flaw has been discovered in Jinher OA 2.0. This affects an unknown pa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10816</guid>
    <pubDate>Mon, 22 Sep 2025 22:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10816</strong></p>
  <p>A security flaw has been discovered in Jinher OA 2.0. This affects an unknown part of the file /c6/Jhsoft.Web.module/ToolBar/GetWordFileName.aspx/?text=GetUrl&style=add of the component XML Handler. Performing manipulation results in xml external entity reference. The attack may be initiated remotely. The exploit has been released to the public and may be exploited.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-10183 – A blind XML External Entity (XXE) injection in the OpenMessaging webservice in T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10183</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10183</guid>
    <pubDate>Tue, 09 Sep 2025 15:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-10183</strong></p>
  <p>A blind XML External Entity (XXE) injection in the OpenMessaging webservice in TecCom TecConnect 4.1 allows an unauthenticated attacker to exfiltrate arbitrary files to an attacker-controlled server. TecConnect 4.1 is considered end-of-life as of December 2023. Users are advised to upgrade to TecCom Connect 5.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10183">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10092 – A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown functi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10092</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10092</guid>
    <pubDate>Mon, 08 Sep 2025 12:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10092</strong></p>
  <p>A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown function of the file /c6/Jhsoft.Web.projectmanage/TaskManage/AddTask.aspx/?Type=add of the component XML Handler. The manipulation results in xml external entity reference. The attack can be executed remotely. The exploit has been made public and could be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10092">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10091 – A vulnerability has been found in Jinher OA up to 1.2. This affects an unknown f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10091</guid>
    <pubDate>Mon, 08 Sep 2025 11:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10091</strong></p>
  <p>A vulnerability has been found in Jinher OA up to 1.2. This affects an unknown function of the file /c6/Jhsoft.Web.projectmanage/ProjectManage/XmlHttp.aspx/?Type=add of the component XML Handler. The manipulation leads to xml external entity reference. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-6984 – The langchain-ai/langchain project, specifically the EverNoteLoader component, i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6984</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6984</guid>
    <pubDate>Thu, 04 Sep 2025 10:42:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-6984</strong></p>
  <p>The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malici…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6984">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-7307 – Sangfor Behavior Management System (also referred to as DC Management System in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-7307</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-7307</guid>
    <pubDate>Wed, 27 Aug 2025 22:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-7307</strong></p>
  <p>Sangfor Behavior Management System (also referred to as DC Management System in Chinese-language documentation) contains an XML external entity (XXE) injection vulnerability in the /src/sangforindex endpoint. A remote unauthenticated attacker can submit crafted XML data containing external entity definitions, leading to potential disclosure of internal files, server-side request forgery (SSRF), o…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-7307">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-57704 – Delta Electronics EIP Builder version 1.11 is vulnerable to a File Parsing XML E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57704</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57704</guid>
    <pubDate>Tue, 26 Aug 2025 07:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-57704</strong></p>
  <p>Delta Electronics EIP Builder version 1.11 is vulnerable to a File Parsing XML External Entity Processing Information Disclosure Vulnerability.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57704">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-47184 – An XML external entities (XXE) injection vulnerability in the /init API endpoint...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47184</guid>
    <pubDate>Thu, 21 Aug 2025 13:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-47184</strong></p>
  <p>An XML external entities (XXE) injection vulnerability in the /init API endpoint in Exagid EX10 before 6.4.0 P20, 7.0.1 P12, and 7.2.0 P08 allows an authenticated, unprivileged attacker to achieve information disclosure and privilege escalation via a crafted ISys XML message.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54988 – Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54988</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54988</guid>
    <pubDate>Wed, 20 Aug 2025 20:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54988</strong></p>
  <p>Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. An attacker may be able to read sensitive data or trigger malicious requests to internal resources or third-party servers. Note that the tika-parser-pdf-module is used as a depend…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54988">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4044 – Improper Restriction of XML External Entity Reference in various Lexmark printer...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4044</guid>
    <pubDate>Tue, 19 Aug 2025 14:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4044</strong></p>
  <p>Improper Restriction of XML External Entity Reference in various Lexmark printer drivers for Windows allows attacker to disclose sensitive information to an arbitrary URL.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-26484 – Dell CloudLink, versions 8.0 through 8.1.1, contains an Improper Restriction of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-26484</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-26484</guid>
    <pubDate>Thu, 14 Aug 2025 15:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-26484</strong></p>
  <p>Dell CloudLink, versions 8.0 through 8.1.1, contains an Improper Restriction of XML External Entity Reference vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-26484">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-40584 – A vulnerability has been identified in SIMOTION SCOUT TIA V5.4 (All versions), S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-40584</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-40584</guid>
    <pubDate>Tue, 12 Aug 2025 12:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-40584</strong></p>
  <p>A vulnerability has been identified in SIMOTION SCOUT TIA V5.4 (All versions), SIMOTION SCOUT TIA V5.5 (All versions), SIMOTION SCOUT TIA V5.6 (All versions < V5.6 SP1 HF7), SIMOTION SCOUT TIA V5.7 (All versions < V5.7 SP1 HF1), SIMOTION SCOUT V5.4 (All versions), SIMOTION SCOUT V5.5 (All versions), SIMOTION SCOUT V5.6 (All versions < V5.6 SP1 HF7), SIMOTION SCOUT V5.7 (All versions < V5.7 SP1 HF…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-40584">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-54992 – OpenKilda is an open-source OpenFlow controller. Prior to version 1.164.0, an XM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54992</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54992</guid>
    <pubDate>Mon, 11 Aug 2025 22:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-54992</strong></p>
  <p>OpenKilda is an open-source OpenFlow controller. Prior to version 1.164.0, an XML external entity (XXE) injection vulnerability was found in OpenKilda which in combination with GHSL-2025-024 allows unauthenticated attackers to exfiltrate information from the instance where the OpenKilda UI is running. This issue may lead to Information disclosure. This issue has been patched in version 1.164.0.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54992">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54254 – Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54254</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54254</guid>
    <pubDate>Tue, 05 Aug 2025 17:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54254</strong></p>
  <p>Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the local file system, scope is changed. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54254">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-19144 – XML External Entity Injection vulnerability in Quantum DXi6702 2.3.0.3 (11449-53...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19144</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19144</guid>
    <pubDate>Fri, 01 Aug 2025 16:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-19144</strong></p>
  <p>XML External Entity Injection vulnerability in Quantum DXi6702 2.3.0.3 (11449-53631 Build304) devices via rest/Users?action=authenticate.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-776</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19144">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36608 – Dell SmartFabric OS10 Software, versions prior to 10.6.0.5, contains an Improper...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36608</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36608</guid>
    <pubDate>Wed, 30 Jul 2025 19:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36608</strong></p>
  <p>Dell SmartFabric OS10 Software, versions prior to 10.6.0.5, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36608">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-26400 – SolarWinds Web Help Desk was reported to be affected by an XML External Entity I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-26400</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-26400</guid>
    <pubDate>Tue, 29 Jul 2025 08:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-26400</strong></p>
  <p>SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosure. A valid, low-privilege access is required unless the attacker had access to the local server to modify configuration files.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-26400">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54445 – Improper Restriction of XML External Entity Reference vulnerability in Samsung E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54445</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54445</guid>
    <pubDate>Wed, 23 Jul 2025 06:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54445</strong></p>
  <p>Improper Restriction of XML External Entity Reference vulnerability in Samsung Electronics MagicINFO 9 Server allows Server Side Request Forgery.This issue affects MagicINFO 9 Server: less than 21.1080.0.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54445">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-7766 – Lantronix Provisioning Manager is vulnerable to XML external entity attacks in c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7766</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7766</guid>
    <pubDate>Tue, 22 Jul 2025 22:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-7766</strong></p>
  <p>Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network devices, leading to unauthenticated remote code execution on hosts with Provisioning Manager installed.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7766">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-34142 – An XML External Entity (XXE) injection vulnerability exists in ETQ Reliance on t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34142</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34142</guid>
    <pubDate>Tue, 22 Jul 2025 13:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-34142</strong></p>
  <p>An XML External Entity (XXE) injection vulnerability exists in ETQ Reliance on the CG (legacy) platform within the `/resources/sessions/sso` endpoint. The SAML authentication handler processes XML input without disabling external entity resolution, allowing crafted SAML responses to invoke external entity references. This could enable attackers to retrieve sensitive files or perform server-side r…</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34142">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36603 – Dell AppSync, version(s) 4.6.0.0, contains an Improper Restriction of XML Extern...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36603</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36603</guid>
    <pubDate>Mon, 21 Jul 2025 17:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36603</strong></p>
  <p>Dell AppSync, version(s) 4.6.0.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering.</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36603">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-7824 – A vulnerability was found in Jinher OA 1.1. It has been rated as problematic. Th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7824</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7824</guid>
    <pubDate>Sat, 19 Jul 2025 13:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-7824</strong></p>
  <p>A vulnerability was found in Jinher OA 1.1. It has been rated as problematic. This issue affects some unknown processing of the file XmlHttp.aspx. The manipulation leads to xml external entity reference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7824">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-7823 – A vulnerability was found in Jinher OA 1.2. It has been declared as problematic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7823</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7823</guid>
    <pubDate>Sat, 19 Jul 2025 13:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-7823</strong></p>
  <p>A vulnerability was found in Jinher OA 1.2. It has been declared as problematic. This vulnerability affects unknown code of the file ProjectScheduleDelete.aspx. The manipulation leads to xml external entity reference. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7823">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-52162 – agorum Software GmbH Agorum core open v11.9.2 &amp; v11.10.1 was discovered to conta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-52162</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-52162</guid>
    <pubDate>Fri, 18 Jul 2025 17:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-52162</strong></p>
  <p>agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to contain an XML External Entity (XXE) via the RSSReader endpoint. This vulnerability allows attackers to access sensitive data via providing a crafted XML input.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52162">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53621 – DSpace open source software is a repository application which provides durable a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53621</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53621</guid>
    <pubDate>Tue, 15 Jul 2025 15:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53621</strong></p>
  <p>DSpace open source software is a repository application which provides durable access to digital resources. Two related XML External Entity (XXE) injection possibilities impact all versions of DSpace prior to 7.6.4, 8.2, and 9.1. External entities are not disabled when parsing XML files during import of an archive (in Simple Archive Format), either from command-line (`./dspace import` command) or…</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53621">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
