Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-611

Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

1,270
Assigned CVEs
43rd
Commonality Rank
7.6
Avg CVSS
0.6%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-611 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 15, 2005
21 years ago
Most Recent CVE
Jul 21, 2026
3 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

1,270 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-9670CRITICAL
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscov
May 29, 20199.899YESYES
CVE-2024-34102CRITICAL
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could re
Jun 13, 20249.898YESYES
CVE-2025-58360CRITICAL
GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XML External Entity (XXE) vulnera
Nov 25, 20259.897YESYES
CVE-2025-2776CRITICAL
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrat
May 7, 20259.895YESYES
CVE-2025-2775HIGH
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator
May 7, 20257.591YESYES
CVE-2022-28219CRITICAL
Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.
Apr 5, 20229.891NOYES
CVE-2017-12629CRITICAL
Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the Run
Oct 14, 20179.890NOYES
CVE-2025-66516CRITICAL
Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML Extern
Dec 4, 20259.887NOYES
CVE-2024-22024HIGH
An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker t
Feb 13, 20248.385NOYES
CVE-2019-13608HIGH
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.
Aug 29, 20197.585YESYES
View all 1,270 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
10%
19%
5.0-5.9
13%
16%
6.0-6.9
28%
26%
7.0-7.9
16%
11%
8.0-8.9
26%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
8 CVEs
0.6% of CVEs· 86th percentile
Metasploit
7 CVEs
0.6% of CVEs· 84th percentile
Nuclei
31 CVEs
2.4% of CVEs· 91st percentile
ExploitDB
52 CVEs
4.1% of CVEs· 94th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products