Vulnerability index

Browse CVEs

70 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Cxf HIGH 7.5
CVE-2026-65432

Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any <wsdl:import> or <…

Fix: 3.6.12 / 4.1.8+
Fix from $1,950 2026-08-06
Lucene.net CRITICAL 9.8
CVE-2026-47898

Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Ap…

Mitigation only
Fix from $2,300 2026-07-03
Cxf CRITICAL 9.8
CVE-2026-49875

Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configuration…

Fix: 4.1.7 / 4.2.2+
Fix from $2,300 2026-06-12
Cxf MEDIUM 5.3
CVE-2026-44618

Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks. Users are recommended to upgrade to …

Fix: 3.6.11 / 4.1.6+
Fix from $1,600 2026-05-22
Opennlp CRITICAL 9.1
CVE-2026-40682

XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0…

Fix: 2.5.9+
Fix from $2,300 2026-05-04
Struts HIGH 8.1
CVE-2025-68493EPSS 37%

Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from…

Fix: 6.1.1+
Fix from $1,950 2026-01-11
Spatial Information System MEDIUM 6.5
CVE-2025-68280

Improper Restriction of XML External Entity Reference vulnerability in Apache SIS. It is possible to write XML files in such a way that, when pars…

Fix: after 1.5
Fix from $1,600 2026-01-05
Tika CRITICAL 9.8
CVE-2025-66516EPSS 79%

Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an a…

Fix: 3.2.2+
Fix from $2,300 2025-12-04
Tika HIGH 8.4
CVE-2025-54988EPSS 9%

Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out…

Fix: 3.2.2+
Fix from $1,950 2025-08-20
Jackrabbit HIGH 8.8
CVE-2025-53689

Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to …

Fix: 2.20.17+
Fix from $1,950 2025-07-14
Ambari HIGH 7.5
CVE-2025-23195

An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie project, allowing an attacker to inject malicious XML entities. This vulnerab…

Fix: 2.7.9+
Fix from $1,950 2025-01-21
Formatting Objects Processor HIGH 7.5
CVE-2024-28168

Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: …

Mitigation only
Fix from $1,950 2024-10-09
Drill HIGH 8.8
CVE-2023-48362

XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands vi…

Fix: 1.21.2+
Fix from $1,950 2024-07-24
Ambari MEDIUM 6.5
CVE-2023-50380

XML External Entity injection in apache ambari versions <= 2.7.7, Users are recommended to upgrade to version 2.7.8, which fixes this issue. More De…

Fix: 2.7.8+
Fix from $1,600 2024-02-27
Cocoon CRITICAL 9.8
CVE-2023-49733

Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. User…

Fix: 2.3.0+
Fix from $2,300 2023-11-30
Ivy HIGH 8.2
CVE-2022-46751

Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache I…

Fix: 2.5.2+
Fix from $1,950 2023-08-21
Nifi HIGH 7.5
CVE-2023-22832

The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references. Flow configurations that i…

Fix: after 1.19.1
Fix from $1,950 2023-02-10
Soap HIGH 7.5
CVE-2022-40705

An Improper Restriction of XML External Entity Reference vulnerability in RPCRouterServlet of Apache SOAP allows an attacker to read arbitrary files …

Mitigation only
Fix from $1,950 2022-09-22
Calcite CRITICAL 9.8
CVE-2022-39135

Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not restrict XML External Entity refe…

Fix: 1.32.0+
Fix from $2,300 2022-09-11
Cloudstack CRITICAL 9.8
CVE-2022-35741EPSS 8%

Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vulnerable to XML external entit…

Fix: 4.16.1.1+
Fix from $2,300 2022-07-18
Jena CRITICAL 9.8
CVE-2022-28890

A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena vers…

Mitigation only
Fix from $2,300 2022-05-05
Nifi HIGH 7.5
CVE-2022-29265

Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration. The Standard Content …

Fix: after 1.16.0
Fix from $1,950 2022-04-30
Any23 CRITICAL 9.1
CVE-2022-25312

An XML external entity (XXE) injection vulnerability was discovered in the Any23 RDFa XSLTStylesheet extractor and is known to affect Any23 versions …

Fix: 2.7+
Fix from $2,300 2022-03-05
Openoffice MEDIUM 6.5
CVE-2021-40439

Apache OpenOffice has a dependency on expat software. Versions prior to 2.1.0 were subject to CVE-2013-0340 a "Billion Laughs" entity expansion denia…

Fix: after 4.1.10
Fix from $1,600 2021-10-07
Jena HIGH 7.5
CVE-2021-39239

A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including ex…

Fix: after 4.1.0
Fix from $1,950 2021-09-16
Any23 CRITICAL 9.1
CVE-2021-38555

An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to affect Any23 versions < 2.5. X…

Fix: 2.5+
Fix from $2,300 2021-09-11
Solr HIGH 7.5
CVE-2021-33813EPSS 19%

An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.

Fix: after 2.0.6
Fix from $1,950 2021-06-16
Nutch CRITICAL 9.1
CVE-2021-23901

An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML externa…

Fix: 1.18+
Fix from $2,300 2021-01-25
Nifi MEDIUM 5.5
CVE-2020-13940

In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted admini…

Fix: after 1.11.4
Fix from $1,600 2020-10-01
Cocoon HIGH 7.5
CVE-2020-11991EPSS 72%

When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to acc…

Fix: after 2.1.12
Fix from $1,950 2020-09-11