← Back to feed Search feed

CWE-611 XML External Entity (XXE) vulnerabilities

7 CVEs — updated 2026-08-04 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-54078veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veHIGH8.724%ileNVD2026-07-29
CVE-2026-54079veraPDF validation provides PDF/A and PDF/UA validation, feature reporting, and metadata repair. From 1.17.35 until 1.30HIGH8.724%ileNVD2026-07-29
CVE-2026-54366CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attackHIGH8.721%ileNVD2026-07-30
CVE-2026-50782Jinher OA C6 contains an XML External Entity (XXE) injection vulnerability in the /c6/JHSoft.Web.HrmAttendance/sp_manageHIGH7.528%ileNVD2026-07-29
CVE-2026-41066lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local filesHIGH7.525%ileMicrosoft2026-04-14
CVE-2026-54082veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veMEDIUM6.514%ileNVD2026-07-29
CVE-2025-36374IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileMEDIUM5.515%ileNVD2026-07-30