Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-611 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 57 | 54 | 0 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▃███
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 2 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 1 · 2026-05 5 · 2026-06 15 · 2026-07 16 · 2026-08 16
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-26171 | 7.5 | 76.1 | — | .NET Denial of Service Vulnerability |
| CVE-2026-48359 | 9.6 | 75.4 | — | Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE'… |
| CVE-2023-35389 | 6.5 | 52.2 | — | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability |
| CVE-2025-61813 | 7.4 | 42.9 | — | ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) |
| CVE-2026-49875 | 9.8 | 42.4 | — | Apache CXF: XML External Entity (XXE) Injection in W3CMultiSchemaFactory and EndpointRe… |
| CVE-2026-45071 | 8.7 | 38.3 | — | Symfony: XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse… |
| CVE-2026-47960 | 7.4 | 38.0 | — | ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) |
| CVE-2026-65432 | 7.5 | 34.2 | — | Apache CXF: XXE via WSDL/XSD import parsing |
| CVE-2026-12788 | 2.1 | 33.4 | — | zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 XML Parser import xml … |
| CVE-2018-25142 | 7.1 | 32.0 | — | NovaRad NovaPACS Diagnostics Viewer 8.5 XML External Entity Injection |
| CVE-2026-55471 | 8.7 | 30.9 | — | HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory |
| CVE-2026-56817 | 8.3 | 30.4 | — | Netty: XML External Entity (XXE) injection via unconfigured XML factory when DTD and en… |
| CVE-2026-6653 | 7.0 | 28.8 | — | libxml2: Use after free in xmlParseInternalSubset via improper entity resolution handling |
| CVE-2026-3603 | 7.1 | 28.7 | — | IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML external en… |
| CVE-2026-40998 | 8.2 | 28.4 | — | Jaxp13 XPath XXE via StreamSource and SAXSource |
| CVE-2026-50782 | 7.5 | 28.1 | — | — |
| CVE-2026-10025 | 9.8 | 28.0 | — | IBM QRadar SIEM has an XML External Entity (XXE) injection vulnerability |
| CVE-2026-47898 | 4.0 | 28.0 | — | Apache Lucene.Net: XXE vulnerability in Lucene.Net.Analysis.Common PatternParser |
| CVE-2026-15803 | 8.7 | 27.5 | — | — |
| CVE-2026-69101 | 8.3 | 27.1 | — | Datavane TIS v5.0.0 XXE Injection via doEditWorkflow Endpoint |