Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-611
Weakness type CWE-611 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 115 | 104 | 8 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▄▄▅█▁
2025-11 1 · 2025-12 2 · 2026-01 1 · 2026-02 0 · 2026-03 1 · 2026-04 4 · 2026-05 6 · 2026-06 15 · 2026-07 16 · 2026-08 20 · 2026-09 40 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-34102 | 9.8 | 100.0 | KEV | XXE can expose crypt key and other secrets granting full admin access |
| CVE-2019-9670 | 9.8 | 100.0 | KEV | Synacor Zimbra Collaboration Suite (ZCS) |
| CVE-2025-2776 | 9.3 | 99.2 | KEV | SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection |
| CVE-2025-58360 | 8.2 | 99.1 | KEV | GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WM… |
| CVE-2025-2775 | 9.3 | 98.7 | KEV | SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection |
| CVE-2019-13608 | 7.5 | 98.2 | KEV | Citrix StoreFront Server |
| CVE-2016-9563 | 6.5 | 97.8 | KEV | SAP NetWeaver |
| CVE-2023-45727 | 7.5 | 88.9 | KEV | North Grid Proself |
| CVE-2025-68493 | 8.1 | 98.8 | — | Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component |
| CVE-2026-26171 | 7.5 | 82.4 | — | .NET Denial of Service Vulnerability |
| CVE-2026-48359 | 9.6 | 61.7 | — | Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE'… |
| CVE-2026-40682 | 9.1 | 56.5 | — | Apache OpenNLP: XXE via Dictionary Parsing in DictionaryEntryPersistor |
| CVE-2026-47960 | 7.4 | 56.3 | — | ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) |
| CVE-2026-49875 | 9.8 | 55.3 | — | Apache CXF: XML External Entity (XXE) Injection in W3CMultiSchemaFactory and EndpointRe… |
| CVE-2023-35389 | 6.5 | 53.5 | — | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability |
| CVE-2026-89260 | 8.7 | 52.8 | — | MoguBlog through 6.2 XML External Entity Injection in the Unauthenticated WeChat Callba… |
| CVE-2026-22016 | 7.5 | 51.6 | — | — |
| CVE-2026-56817 | 8.3 | 51.3 | — | Netty: XML External Entity (XXE) injection via unconfigured XML factory when DTD and en… |
| CVE-2026-65432 | 7.5 | 49.4 | — | Apache CXF: XXE via WSDL/XSD import parsing |
| CVE-2026-10025 | 9.8 | 49.2 | — | IBM QRadar SIEM has an XML External Entity (XXE) injection vulnerability |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| ibm | 23 |
| apache | 9 |
| adobe | 4 |
| cisco | 3 |
| dell | 3 |
| jetbrains | 3 |
| verapdf | 3 |
| docling-project | 2 |
| eclipse foundation | 2 |
| geoserver | 2 |
| microsoft | 2 |
| nextgen healthcare | 2 |
| red hat | 2 |
| rti | 2 |
| sap_se | 2 |