目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CWE-611 XML外部实体引用的不恰当限制(XXE) 类漏洞列表 482

CWE-611 XML外部实体引用的不恰当限制(XXE) 类弱点 482 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-611 指 XML 外部实体注入漏洞,属于处理 XML 文档时的安全缺陷。攻击者通过构造包含恶意外部实体的 XML 数据,诱导系统读取服务器本地文件或发起 SSRF 请求,从而泄露敏感信息或探测内网。开发者应避免使用默认配置解析 XML,禁用外部实体解析功能,并对输入数据进行严格校验与过滤,确保仅处理受信任的实体引用。

MITRE CWE 官方描述
CWE:CWE-611 XML外部实体引用限制不当 英文:该产品处理包含XML实体的XML文档,这些实体的URI可解析到预期控制范围之外的文档,导致该产品将不正确的文档嵌入其输出中。
常见影响 (3)
Confidentiality Read Application Data, Read Files or Directories
If the attacker is able to include a crafted DTD and a default entity resolver is enabled, the attacker may be able to access arbitrary files on the system. By submitting an XML file that defines an external entity with a file:// URI, an attacker can cause the processing application to read the co…
Integrity Bypass Protection Mechanism
An attacker may supply a crafted DTD using URIs with schemes such as http://, forcing the application to make outgoing HTTP requests to servers that the attacker cannot reach directly, which can be used to bypass firewall restrictions; hide the source of attacks such as port scanning; or otherwise l…
Availability DoS: Resource Consumption (CPU), DoS: Resource Consumption (Memory)
The product could consume excessive CPU cycles or memory using a URI that points to a large file, or a device that always returns data such as /dev/random. Alternately, the URI could reference a file that contains many nested or recursive entity references to further slow down parsing.
缓解措施 (1)
Implementation, System Configuration Many XML parsers and validators can be configured to disable external entity expansion.
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-19614 CyberELF NanoXML XXE注入漏洞 — NanoXML 5.3 Medium 2026-09-08
CVE-2026-71375 Cosminexus组件容器 XXE漏洞 — Cosminexus Component Container 7.4 High 2026-09-08
CVE-2026-76958 SAP Integration Suite XML外部实体漏洞 — SAP Integration Suite 8.5 High 2026-09-08
CVE-2026-17443 IBM App Connect Enterprise 输入验证错误漏洞 — App Connect Enterprise 5.3 Medium 2026-09-04
CVE-2026-17444 IBM App Connect Enterprise 输入验证错误漏洞 — App Connect Enterprise 5.3 Medium 2026-09-04
CVE-2026-81832 IBM App Connect Enterprise 输入验证错误漏洞 — App Connect Enterprise 7.7 High 2026-09-04
CVE-2026-82525 Exterro FTK Imager 输入验证错误漏洞 — FTK Imager 5.5 Medium 2026-09-03
CVE-2026-82918 KEYENCE XG VisionTerminal 输入验证错误漏洞 — XG-X VisionTerminal 5.5 Medium 2026-09-03
CVE-2026-17615 RESTEasy 输入验证错误漏洞 — Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.3.SP1 7.5 High 2026-08-31
CVE-2026-82880 YaCy Search Engine YaCy 输入验证错误漏洞 — yacy_search_server 7.5 High 2026-08-31
CVE-2026-55848 mapfish-print 输入验证错误漏洞 — mapfish-print 8.6 High 2026-08-28
CVE-2026-76572 Public Knowledge Project PKP Web Application Library 输入验证错误漏洞 — pkp-lib 4.7 Medium 2026-08-19
CVE-2026-20320 Cisco BroadWorks 输入验证错误漏洞 — Cisco BroadWorks 7.5 High 2026-08-19
CVE-2026-67268 Dell Command Update 输入验证错误漏洞 — Dell Command Update (DCU) 6.5 Medium 2026-08-19
CVE-2026-70423 Dell OpenManage Enterprise 输入验证错误漏洞 — OpenManage Enterprise 6.5 Medium 2026-08-19
CVE-2026-75058 JetBrains IntelliJ IDEA 输入验证错误漏洞 — IntelliJ IDEA 5.5 Medium 2026-08-17
CVE-2026-75055 JetBrains IntelliJ IDEA 输入验证错误漏洞 — IntelliJ IDEA 5.5 Medium 2026-08-17
CVE-2026-69101 Datavane TIS 输入验证错误漏洞 — tis 7.7 High 2026-08-14
CVE-2026-18715 IBM i 输入验证错误漏洞 — i 6.5 Medium 2026-08-13
CVE-2026-15803 Eclipse RDF4J 输入验证错误漏洞 — Eclipse RDF4J 8.7 High 2026-08-12
CVE-2026-16999 Ministry of Justice UYAP Document Editor 输入验证错误漏洞 — UYAP Document Editor 6.3 Medium 2026-08-12
CVE-2026-73235 FreeCAD 输入验证错误漏洞 — FreeCAD 6.1 Medium 2026-08-11
CVE-2026-58248 SAP BusinessObjects Business Intelligence Platform 输入验证错误漏洞 — SAP BusinessObjects Business Intelligence 6.5 Medium 2026-08-11
CVE-2026-16626 Jaspersoft JasperReports Server 输入验证错误漏洞 — JasperReports Server 9.3 Critical 2026-08-10
CVE-2026-65432 Apache CXF WSDL/XSD导入解析XXE漏洞 — Apache CXF - - 2026-08-06
CVE-2026-10025 IBM QRadar 输入验证错误漏洞 — QRadar 8.2 High 2026-08-05
CVE-2026-14304 Eclipse Accessibility Tools Framework 输入验证错误漏洞 — Eclipse Accessibility Tools Framework (ACTF) 4.6 Medium 2026-08-05
CVE-2025-36374 IBM DataPower Gateway 输入验证错误漏洞 — DataPower Gateway 10.6CD 5.5 Medium 2026-07-30
CVE-2026-54366 Gladinet CentreStack 输入验证错误漏洞 — CentreStack 7.5 High 2026-07-30
CVE-2026-54082 veraPDF veraPDF-validation 输入验证错误漏洞 — veraPDF-validation 6.5 Medium 2026-07-29

CWE-611(XML外部实体引用的不恰当限制(XXE)) 是常见的弱点类别,本平台收录该类弱点关联的 482 条 CVE 漏洞。