Safeguard
Tag

cwe-611

Safeguard articles tagged "cwe-611" — guides, analysis, and best practices for software supply chain and application security.

13 articles

Vulnerability Analysis

CVE-2019-13608: Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability

CVE-2019-13608 affects Citrix StoreFront Server and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2019-9670: Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference

CVE-2019-9670 affects Synacor Zimbra Collaboration Suite (ZCS) and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-01-10.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2016-9563: SAP NetWeaver XML External Entity (XXE) Vulnerability

CVE-2016-9563 affects SAP NetWeaver and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2024-34102: Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability

CVE-2024-34102 affects Adobe Commerce and Magento Open Source and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-07-17.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2023-45727: North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability

CVE-2023-45727 affects North Grid Proself and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-12-03.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2025-2776: SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability

CVE-2025-2776 affects SysAid SysAid On-Prem and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-07-22.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2025-2775: SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability

CVE-2025-2775 affects SysAid SysAid On-Prem and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-07-22.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2025-58360: OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability

CVE-2025-58360 affects OSGeo GeoServer and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-12-11.

Sep 17, 20263 min read
Vulnerability Analysis

XML External Entity (XXE) injection explained

XXE injection lets attackers abuse XML parsers to read files, hit cloud metadata via SSRF, or crash servers — here's how it works and how to stop it.

Aug 3, 20267 min read
Application Security

Finding and fixing XXE vulnerabilities across common XML parsers

XXE is tracked as CWE-611 and lives in OWASP's misconfiguration category — because most XML parsers ship unsafe by default.

Jul 13, 20267 min read
Industry Analysis

XXE Prevention in C++: Removing libxml2 XML_PARSE_NOENT

How the libxml2 XML_PARSE_NOENT flag enables XXE in C++ codebases, the real CVEs behind it, and the exact code changes needed to remove it safely.

Jul 4, 20267 min read
Vulnerability Guides

What Is XXE (XML External Entity Injection)?

XXE abuses an XML parser's ability to load external entities to read local files, reach internal services, or knock a server offline. Here is how to stop it.

Jul 1, 20265 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.