cwe-611
Safeguard articles tagged "cwe-611" — guides, analysis, and best practices for software supply chain and application security.
13 articles
CVE-2019-13608: Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability
CVE-2019-13608 affects Citrix StoreFront Server and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2019-9670: Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference
CVE-2019-9670 affects Synacor Zimbra Collaboration Suite (ZCS) and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-01-10.
CVE-2016-9563: SAP NetWeaver XML External Entity (XXE) Vulnerability
CVE-2016-9563 affects SAP NetWeaver and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2024-34102: Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability
CVE-2024-34102 affects Adobe Commerce and Magento Open Source and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-07-17.
CVE-2023-45727: North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability
CVE-2023-45727 affects North Grid Proself and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-12-03.
CVE-2025-2776: SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability
CVE-2025-2776 affects SysAid SysAid On-Prem and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-07-22.
CVE-2025-2775: SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability
CVE-2025-2775 affects SysAid SysAid On-Prem and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-07-22.
CVE-2025-58360: OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability
CVE-2025-58360 affects OSGeo GeoServer and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-12-11.
XML External Entity (XXE) injection explained
XXE injection lets attackers abuse XML parsers to read files, hit cloud metadata via SSRF, or crash servers — here's how it works and how to stop it.
Finding and fixing XXE vulnerabilities across common XML parsers
XXE is tracked as CWE-611 and lives in OWASP's misconfiguration category — because most XML parsers ship unsafe by default.
XXE Prevention in C++: Removing libxml2 XML_PARSE_NOENT
How the libxml2 XML_PARSE_NOENT flag enables XXE in C++ codebases, the real CVEs behind it, and the exact code changes needed to remove it safely.
What Is XXE (XML External Entity Injection)?
XXE abuses an XML parser's ability to load external entities to read local files, reach internal services, or knock a server offline. Here is how to stop it.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.