Vulnerability index

Browse CVEs

23 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Experience Manager CRITICAL 9.6
CVE-2026-48359

Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary…

Fix: after 2020.5.0
Fix from $2,300 2026-07-14
Coldfusion HIGH 7.4
CVE-2026-47960

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that c…

Mitigation only
Fix from $1,950 2026-06-09
Coldfusion MEDIUM 6.8
CVE-2025-61821

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerabili…

Mitigation only
Fix from $1,600 2025-12-10
Coldfusion MEDIUM 6.2
CVE-2025-61823

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerabili…

Mitigation only
Fix from $1,600 2025-12-10
Coldfusion HIGH 7.4
CVE-2025-61813

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerabili…

Mitigation only
Fix from $1,950 2025-12-10
Experience Manager Forms HIGH 8.6
CVE-2025-54254EPSS 77%

Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability t…

Fix: after 6.5.23.0
Fix from $1,950 2025-08-05
Coldfusion MEDIUM 6.8
CVE-2025-49544

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerabili…

Mitigation only
Fix from $1,600 2025-07-08
Coldfusion CRITICAL 9.3
CVE-2025-49535

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerabili…

Mitigation only
Fix from $2,300 2025-07-08
Acrobat MEDIUM 6.3
CVE-2024-49535

Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by an Improper Restriction of X…

Fix: 20.005.30748 / 24.001.30225+
Fix from $1,600 2024-12-10
Commerce CRITICAL 9.8
CVE-2024-34102 KEVEPSS 100%

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XX…

Fix: 1.5.0+
Fix from $2,300 2024-06-13
Robohelp Server HIGH 7.5
CVE-2023-22274

Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that c…

Fix: after 11.4
Fix from $1,950 2023-11-17
Coldfusion HIGH 7.5
CVE-2022-42341EPSS 36%

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference…

Mitigation only
Fix from $1,950 2022-10-14
Coldfusion HIGH 7.5
CVE-2022-38419EPSS 53%

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference…

Patch available
Fix from $1,950 2022-10-14
Experience Manager CRITICAL 9.8
CVE-2021-40722

AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) injection vulnerability that c…

Fix: after 6.5.10.0
Fix from $2,300 2022-01-13
Experience Manager HIGH 7.5
CVE-2019-8086EPSS 23%

Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sen…

Mitigation only
Fix from $1,950 2019-10-25
Experience Manager HIGH 7.5
CVE-2019-8087

Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sen…

Mitigation only
Fix from $1,950 2019-10-25
Experience Manager HIGH 7.5
CVE-2019-8082

Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitiv…

Mitigation only
Fix from $1,950 2019-10-25
Campaign HIGH 7.5
CVE-2019-7847

Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Improper Restriction of XML External Entity Reference ('XXE') vulnerability.…

Fix: after 18.10.5.8984
Fix from $1,950 2019-07-18
Coldfusion HIGH 7.5
CVE-2018-4942

Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Unsafe XML External Entity Processin…

Mitigation only
Fix from $1,950 2018-05-19
Coldfusion HIGH 7.5
CVE-2017-11286EPSS 8%

Adobe ColdFusion has an XML external entity (XXE) injection vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update…

Patch available
Fix from $1,950 2017-12-01
Digital Editions HIGH 7.5
CVE-2017-11272EPSS 13%

Adobe Digital Editions 4.5.4 and earlier has a security bypass vulnerability.

Fix: after 4.5.5
Fix from $1,950 2017-08-11
Coldfusion HIGH 8.6
CVE-2016-4264EPSS 69%

The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 allows remote attackers to read arbitrary files o…

Fix: after 11.0
Fix from $1,950 2016-09-01
Acrobat HIGH 7.5
CVE-2005-1306EPSS 15%

The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript contain…

Patch available
Fix from $1,950 2005-06-15