Dom4j is a widely embedded XML processing library used across Java applications, despite its narrow product scope, making its vulnerabilities potentially significant for downstream consumers. The recurring exposure centers on XML entity and injection attacks, particularly improper restriction of external entity references and blind XPath injection, which reflect the parsing and document-traversal complexity inherent to an XML DOM implementation. Current severity, exploitation activity, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dom4j Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-10683CRITICAL dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation fr | May 1, 2020 | 9.8 | 30 | NO | NO |
CVE-2018-1000632HIGH dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering wi | Aug 20, 2018 | 7.5 | 27 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dom4j Project.
Media articles that mention a CVE ID that affects a product developed by Dom4j Project — matched by CVE ID, not by vendor name.