← Back to feed Search feed

CWE-611 XML External Entity (XXE) vulnerabilities

13 CVEs — updated 2026-09-18 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-12666IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1HIGH8.119%ileNVD2026-09-15
CVE-2026-16432IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage PxXMLInput operator could allow a remote authenticated attackeHIGH7.728%ileNVD2026-09-14
CVE-2026-13107IBM Business Automation Workflow containers and traditional may use programming model artifacts that are vulnerable to XHIGH7.130%ileNVD2026-09-14
CVE-2026-13275IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1HIGH7.117%ileNVD2026-09-14
CVE-2026-13285IBM MQ is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could HIGH7.132%ileNVD2026-09-14
CVE-2026-13287IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1HIGH7.132%ileNVD2026-09-14
CVE-2026-12756IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attaHIGH7.142%ileNVD2026-09-14
CVE-2026-91197Flowable flowable-engine through 8.0.0 contains an XML external entity injection vulnerability in ProcessDiagramLayoutFaHIGH7.119%ileNVD2026-09-14
CVE-2026-12667IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1HIGH7.130%ileNVD2026-09-15
CVE-2026-12752IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attaHIGH7.142%ileNVD2026-09-15
CVE-2026-13265IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1MEDIUM6.813%ileNVD2026-09-14
CVE-2026-76427A vulnerability in the offline profiler feed service of Cisco ISE could allow an authenticated, remote attacker to read MEDIUM4.927%ileNVD2026-09-16
CVE-2026-76446A vulnerability in an API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read specific&MEDIUM4.923%ileNVD2026-09-16