SimpleXML Project maintains a specialized XML parsing library with a narrow product footprint centered on the SimpleXML parser itself. The vulnerability signal in this vendor's disclosures centers on improper restriction of XML external entity references, a parsing-layer weakness class inherent to XML processing. Current vulnerability counts, severity distribution, exploitation activity, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Simplexml Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-1000190CRITICAL SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on. | Nov 17, 2017 | 9.1 | 27 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Simplexml Project.
Media articles that mention a CVE ID that affects a product developed by Simplexml Project — matched by CVE ID, not by vendor name.