boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-611

Weakness type CWE-611 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
57540

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▃███

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 2 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 1 · 2026-05 5 · 2026-06 15 · 2026-07 16 · 2026-08 16

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-261717.576.1.NET Denial of Service Vulnerability
CVE-2026-483599.675.4Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE'…
CVE-2023-353896.552.2Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
CVE-2025-618137.442.9ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
CVE-2026-498759.842.4Apache CXF: XML External Entity (XXE) Injection in W3CMultiSchemaFactory and EndpointRe…
CVE-2026-450718.738.3Symfony: XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse…
CVE-2026-479607.438.0ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
CVE-2026-654327.534.2Apache CXF: XXE via WSDL/XSD import parsing
CVE-2026-127882.133.4zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 XML Parser import xml …
CVE-2018-251427.132.0NovaRad NovaPACS Diagnostics Viewer 8.5 XML External Entity Injection
CVE-2026-554718.730.9HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory
CVE-2026-568178.330.4Netty: XML External Entity (XXE) injection via unconfigured XML factory when DTD and en…
CVE-2026-66537.028.8libxml2: Use after free in xmlParseInternalSubset via improper entity resolution handling
CVE-2026-36037.128.7IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML external en…
CVE-2026-409988.228.4Jaxp13 XPath XXE via StreamSource and SAXSource
CVE-2026-507827.528.1
CVE-2026-100259.828.0IBM QRadar SIEM has an XML External Entity (XXE) injection vulnerability
CVE-2026-478984.028.0Apache Lucene.Net: XXE vulnerability in Lucene.Net.Analysis.Common PatternParser
CVE-2026-158038.727.5
CVE-2026-691018.327.1Datavane TIS v5.0.0 XXE Injection via doEditWorkflow Endpoint

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
ibm5
apache4
adobe3
dell3
jetbrains3
verapdf3
docling-project2
eclipse foundation2
microsoft2
spring2
arekinath1
asseco1
cisco1
datavane1
dropbox1