Skip to content
Threat Feed

Tag

XXE

27 briefs RSS
high advisory

XML External Entity Injection in IBM Business Automation Workflow

IBM Business Automation Workflow contains a vulnerability in default programming artifacts that allows for XML External Entity (XXE) injection attacks, potentially enabling unauthorized file access or server-side request forgery.

Business Automation Workflow web-vulnerability xxe ibm
1t 1c
high advisory

MoguBlog XML External Entity Injection in WeChat Callback

MoguBlog versions through 6.2 are vulnerable to unauthenticated XML External Entity (XXE) injection via the WeChat callback handler, allowing arbitrary file read and outbound SSRF.

MoguBlog web-vulnerability xxe injection
1r 2t 1c
medium advisory

XXE Vulnerability in IBM webMethods Integration Server

IBM webMethods Integration Server 11.1 is vulnerable to an XML External Entity (XXE) injection flaw that allows unauthenticated attackers to exfiltrate sensitive files or trigger denial of service via memory exhaustion.

webMethods Integration Server web-vulnerability xxe injection
1t 1c
high advisory

XML Injection Vulnerability in @xmldom/xmldom via Processing Instruction Targets

The @xmldom/xmldom library fails to validate the target parameter in createProcessingInstruction, enabling attackers to break out of XML processing instructions and inject arbitrary content when serializing with the requireWellFormed flag.

@xmldom/xmldom +2 injection xss xxe vulnerability
1t 1c
high advisory

XML External Entity Vulnerability in IBM App Connect Enterprise and Integration Bus

IBM App Connect Enterprise and IBM Integration Bus for z/OS SAP Adapter components are susceptible to an XML External Entity (XXE) vulnerability, potentially allowing unauthenticated information disclosure or denial of service.

App Connect Enterprise +1 vulnerability xxe ibm integration
1t 1c
high threat

Exploitation of CVE-2024-30043 XXE in Microsoft SharePoint Server

A publicly available exploit for CVE-2024-30043 allows unauthenticated remote attackers to perform XML External Entity (XXE) injection against Microsoft SharePoint Server via URL parsing confusion, potentially leading to sensitive data disclosure.

exploited SharePoint Server vulnerability xxe sharepoint cve-2024-30043
1t 1c
high advisory

RESTEasy XML External Entity Vulnerability in SourceProvider

An XML External Entity (XXE) vulnerability in RESTEasy's SourceProvider allows unauthenticated attackers to perform arbitrary remote file reads via malicious XML input.

RESTEasy web-application xxe vulnerability
1t 1c
high advisory

XXE Vulnerability in MapFish Print

MapFish Print is susceptible to an XML External Entity (XXE) injection vulnerability via the GML layer processing feature, allowing attackers to perform arbitrary file reads or Server-Side Request Forgery (SSRF).

print-lib +1 xxe cve-2026-55848 vulnerability webserver
2t 1c
high advisory

Datavane TIS XXE Vulnerability CVE-2026-69101

Datavane TIS v5.0.0 is vulnerable to XML external entity injection in the doEditWorkflow endpoint, allowing authenticated attackers to perform SSRF and exfiltrate sensitive local files.

TIS web-vulnerability xxe ssrf data-exfiltration
1r 1t 1c
high advisory

Pre-Authentication XXE Vulnerability in SimpleSAMLphp

A proof-of-concept exploit has been published for a pre-authentication XML External Entity (XXE) vulnerability in SimpleSAMLphp and the Saml2 Library, enabling arbitrary file read by unauthenticated remote attackers.

SimpleSAMLphp +1 web-vulnerability xxe authentication
1t 2c
high advisory

XXE Injection Vulnerability in IBM QRadar

IBM QRadar contains an XML External Entity (XXE) injection vulnerability in the event processing pipeline that allows unauthenticated attackers to read arbitrary files from the system.

QRadar vulnerability cve-2026-10025 xxe siem
1t 1c
high advisory

CVE-2026-54366 CentreStack XXE Injection

CentreStack versions prior to 17.4 are vulnerable to an unauthenticated XXE injection via the SharePoint storage configuration handler, allowing attackers to exfiltrate sensitive server-side files.

CentreStack xxe vulnerability web-application
1r 2t 1c
high advisory

veraPDF Validation XXE via Rich Text

An XML External Entity (XXE) injection vulnerability (CVE-2026-54078, CWE-611) in the veraPDF-validation library's `validation-model` module allows a remote attacker to read arbitrary files from the server's file system and perform Server-Side Request Forgery by submitting a crafted PDF containing a malicious rich-text entry, which is then parsed by an insecure `DocumentBuilderFactory`.

validation-model +3 xml-external-entity-injection xxe server-side-request-forgery ssrf pdf java
3t
high advisory

veraPDF Validation Module XML External Entity Injection Vulnerability (CVE-2026-54079)

A critical XML External Entity Injection (XXE) vulnerability, CVE-2026-54079, in veraPDF's validation-model module allows a remote attacker to read arbitrary files on the server file system or perform Server-Side Request Forgery (SSRF) by submitting a crafted PDF containing a malicious XFA stream, due to insecure XML parsing defaults.

veraPDF validation-model +3 xxe xml-external-entity pdf server-side-request-forgery vulnerability
4t
high advisory

Netty XML Injection Vulnerability (CVE-2026-56817)

A misconfiguration vulnerability (CVE-2026-56817) in Netty's XmlDecoder component allows attackers to send XML with DOCTYPE declarations to an unconfigured XML factory, potentially leading to XML External Entity (XXE) injection if the underlying Aalto XML parser resolves external entities, impacting Netty applications using `netty-codec-xml` versions 4.1.0.Final through 4.1.135.Final and 4.2.0.Final through 4.2.15.Final.

netty-codec-xml +1 netty xml xxe vulnerability java server-side web-application
1r 1t 1c
high advisory

Improper Restriction of XML External Entity Reference in Netcad Software NetGIS (CVE-2026-8396)

A critical XML External Entity (XXE) vulnerability, CVE-2026-8396, in Netcad Software Inc.'s NetGIS allows unauthenticated remote attackers to perform serialized data external linking, potentially leading to sensitive information disclosure or server-side request forgery.

NetGIS xxe vulnerability web-application information-disclosure cwe-611
2t 1c
high advisory

OpenRemote Incomplete Fix for XXE in KNXProtocol Leads to Arbitrary File Read (CVE-2026-54640)

An incomplete fix for CVE-2026-40882 in OpenRemote's KNXProtocol module (specifically in versions <= 1.24.1 of the agent module) allows authenticated users to perform an XML External Entity (XXE) injection, enabling arbitrary file read from the server's filesystem, including sensitive configuration files and potentially leading to server-side request forgery (SSRF) against cloud metadata endpoints or internal services, without requiring administrator access.

OpenRemote Agent xxe arbitrary-file-read ssrf openremote iot vulnerability incomplete-fix
4t 1c 3i
medium advisory

CVE-2026-3603: IBM Engineering Lifecycle Management XXE Vulnerability

IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 are vulnerable to XML external entity injection (XXE), allowing an authenticated attacker to expose sensitive information or consume memory resources.

Engineering Lifecycle Management 7.0.3 +2 cve xxe injection
2r 1t 1c
critical advisory

Adobe Commerce XXE Vulnerability (CVE-2024-34102) Exploit Released

A public exploit, named CosmicSting, has been released for CVE-2024-34102, an XML External Entity (XXE) Injection vulnerability in Adobe Commerce allowing for unauthenticated remote file read, SSRF, and potential RCE.

Commerce cve-2024-34102 xxe adobe commerce magento
2r 1t 1c 1i
high advisory

Vvveb CMS XML External Entity Injection Vulnerability

Vvveb before 1.0.8.2 is vulnerable to XML external entity (XXE) injection in the admin import feature, allowing authenticated site administrators to read arbitrary files and modify database records, potentially leading to privilege escalation.

Vvveb +1 xxe vulnerability injection
2r 3t 1c
critical advisory

Pachno 1.0.6 XML External Entity Injection Vulnerability

Pachno 1.0.6 is vulnerable to XML external entity injection, allowing unauthenticated attackers to read arbitrary files by injecting malicious XML entities into wiki content due to unsafe XML parsing in the TextParser helper.

xxe cve-2026-40042 pachno web-application
2r 2t 1c 1i
high advisory

OpenEMR XXE Vulnerability (CVE-2026-33913)

OpenEMR before version 8.0.0.3 is vulnerable to XML External Entity (XXE) injection, allowing an authenticated user with access to the Carecoordination module to upload a crafted CCDA document and read arbitrary files from the server.

cve-2026-33913 xxe openemr web-application
2r
high advisory

libxml2 Vulnerability Allows XXE Attacks

A remote, anonymous attacker can exploit a vulnerability in libxml2 to manipulate files or cause a denial of service.

libxml2 xxe vulnerability
2r 2t
high advisory

WSO2 Products Vulnerable to XML External Entity (XXE) Injection via CVE-2024-2374

CVE-2024-2374 describes an XML External Entity (XXE) vulnerability in multiple WSO2 products, where improperly configured XML parsers allow attackers to inject malicious XML payloads to include external resources, leading to confidential file access, limited HTTP resource access, and denial-of-service attacks.

WSO2 xxe cve-2024-2374 xml vulnerability attack cloud network
2r 2t
high advisory

changedetection.io XXE Vulnerability

A vulnerability in changedetection.io versions 0.54.9 and earlier allows a remote attacker to perform XML External Entity (XXE) attacks, potentially exposing sensitive local files.

changedetection.io XXE vulnerability
2r 1t
high advisory

xmldom XML Injection Vulnerability

The xmldom package is vulnerable to XML injection. The package serializes DocumentType node fields (internalSubset, publicId, systemId) verbatim without any escaping or validation. When these fields are set programmatically to attacker-controlled strings, XMLSerializer.serializeToString can produce output where the DOCTYPE declaration is terminated early and arbitrary markup appears outside it. To address this applications that pass untrusted data to createDocumentType() or write untrusted values directly to a DocumentType node's publicId, systemId, or internalSubset properties should audit all serializeToString() call sites and add the option.

@xmldom/xmldom +1 xml-injection xxe dom xmldom
2r 1t 1c updated
high advisory

lxml Library Vulnerable to XXE Attacks via iterparse() and ETCompatXMLParser()

lxml versions before 6.1.0 are vulnerable to XML External Entity (XXE) attacks when using iterparse() or ETCompatXMLParser() with default settings, potentially allowing local file reads.

lxml library lxml XXE vulnerability CVE-2026-41066
2r 1t