Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

131 advisories

Loading
MapFish Print has XXE that allows reading arbitrary files of certain types High
CVE-2026-55848 was published for org.mapfish.print:print-lib (Maven) Aug 28, 2026
zneek Credited to zneek
veraPDF Validation XXE via Rich Text High
CVE-2026-54078 was published for org.verapdf:validation-model (Maven) Jul 29, 2026
wodzen Credited to wodzen
veraPDF Validation XXE via XFA High
CVE-2026-54079 was published for org.verapdf:validation-model (Maven) Jul 29, 2026
wodzen Credited to wodzen
Netty XML: Injection / Risky Sink — unconfigured XML factory with active DTD and entity handling High
CVE-2026-56817 was published for io.netty:netty-codec-xml (Maven) Jul 22, 2026
dyingman1 Credited to dyingman1
Spring Web Services: Jaxp13 XPath XXE via StreamSource and SAXSource High
CVE-2026-40998 was published for org.springframework.ws:spring-xml (Maven) Jun 11, 2026
Alkacon OpenCms is vulnerable to XXE when the <!DOCTYPE> refers to an external host High
CVE-2023-42346 was published for org.opencms:opencms-core (Maven) May 8, 2026
Alkacon OpenCms allows remote unauthenticated attackers to obtain sensitive information High
CVE-2023-42344 was published for org.opencms:opencms-core (Maven) May 8, 2026
OpenRemote has XXE in Velbus Asset Import High
CVE-2026-40882 was published for io.openremote:openremote-manager (Maven) Apr 15, 2026
KKC73 Credited to KKC73
AssertJ has XML External Entity (XXE) vulnerability when parsing untrusted XML via isXmlEqualTo assertion High
CVE-2026-24400 was published for org.assertj:assertj-core (Maven) Jan 26, 2026
wxt201 Credited to wxt201 and scordio scordio scordio
Apache Struts 2 is Missing XML Validation High
CVE-2025-68493 was published for com.opensymphony:xwork (Maven) Jan 11, 2026
GeoServer is vulnerable to Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature High
CVE-2025-58360 was published for org.geoserver.web:gs-web-app (Maven) Nov 25, 2025
xbow-security Credited to xbow-security and jodygarnett jodygarnett jodygarnett
CycloneDX Core (Java): BOM validation is vulnerable to XML External Entity injection High
CVE-2025-64518 was published for org.cyclonedx:cyclonedx-core-java (Maven) Nov 10, 2025
nscuro Credited to nscuro and BrightKn1ght BrightKn1ght BrightKn1ght
Jenkins JDepend Plugin vulnerable to XML external entity attacks High
CVE-2025-64134 was published for org.jenkins-ci.plugins:jdepend (Maven) Oct 29, 2025
Apache Jackrabbit vulnerable to blind XXE attack due to insecure document build High
CVE-2025-53689 was published for org.apache.jackrabbit:jackrabbit-core (Maven) Jul 14, 2025
Allure Report allows Improper XXE Restriction via DocumentBuilderFactory High
CVE-2025-52888 was published for io.qameta.allure.plugins:junit-xml-plugin (Maven) Jun 25, 2025
DerekHaber Credited to DerekHaber and baev baev baev
GeoNetwork affected by XML External Entity (XXE) processing vulnerability in WFS indexing REST API endpoint High
GHSA-2p76-gc46-5fvc was published for org.geonetwork-opensource:gn-web-app (Maven) Jun 10, 2025
jodygarnett Credited to jodygarnett and josegar74 josegar74 josegar74
[XBOW-025-068] XML External Entity (XXE) Processing Vulnerability in GeoServer WFS Service High
CVE-2025-30220 was published for org.geoserver.web:gs-web-app (Maven) Jun 10, 2025
xbow-security Credited to xbow-security, YacineF, aaime, and jodygarnett YacineF YacineF
aaime aaime jodygarnett jodygarnett
The XWiki JIRA extension allows data leak through an XXE attack by using a fake JIRA server High
CVE-2025-31487 was published for org.xwiki.contrib.jira:jira-macro-default (Maven) Apr 4, 2025
XXE vulnerability in XSLT parsing in `org.hl7.fhir.publisher` High
CVE-2024-52807 was published for org.hl7.fhir.publisher:org.hl7.fhir.publisher.cli (Maven) Jan 24, 2025
dotasek Credited to dotasek
Ucum-java has an XXE vulnerability in XML parsing High
CVE-2024-55887 was published for org.fhir:ucum (Maven) Dec 13, 2024
XXE vulnerability in XSLT parsing in `org.hl7.fhir.core` High
CVE-2024-52007 was published for ca.uhn.hapi.fhir:org.hl7.fhir.dstu2016may (Maven) Nov 8, 2024
soaringlion Credited to soaringlion
HAPI FHIR XML External Entity (XXE) vulnerability High
CVE-2024-51132 was published for ca.uhn.hapi.fhir:org.hl7.fhir.convertors (Maven) Nov 5, 2024
DataEase has an XML External Entity Reference vulnerability High
CVE-2024-46985 was published for io.dataease:common (Maven) Sep 23, 2024
flylzj Credited to flylzj
Gematik Referenzvalidator has an XXE vulnerability that can lead to a Server Side Request Forgery attack High
CVE-2024-46984 was published for de.gematik.refv.commons:commons (Maven) Sep 19, 2024
ProTip! Advisories are also available from the GraphQL API