Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 16.538 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 179 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Search results for: XML External Entity

Displaying 1 - 25 results out of 69

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
VMWare Cloud Foundation NSX-V - XML External Entity (XXE)Network Scanner

Critical(9.1)

No
Cybersecurity Infrastructure Security Agency (CISA)Citrix StoreFront Server - XML External EntityNetwork Scanner

High(7.5)

No
Apache Tika - XML External Entity InjectionNetwork Scanner

Critical(9.8)

No
Ektron CMS Blogs xmlrpc.aspx - XML External Entity InjectionNetwork Scanner

High

No
Apache OFBiz - XML External Entity InjectionNetwork Scanner

High(7.5)

No
Episerver 7 - Blind XML External Entity InjectionNetwork Scanner

High(7.5)

No
Cybersecurity Infrastructure Security Agency (CISA)GeoServer - XML External Entity InjectionNetwork Scanner

High(8.2)

No
Guralp MAN-EAM-0003 3.2.4 - XML External Entity (XXE)Network Scanner

High(7.5)

No
Apache Tika 1.13 - 3.2.1 XXE VulnerabilityNetwork Scanner

Critical(9.8)

No
Akamai CloudTest < 60 2025.06.02 - XML External Entity (XXE)Network Scanner

Critical(9.1)

No
GeoServer WFS - XXE Processing VulnerabilityNetwork Scanner

Critical(9.9)

No
LabKey Server 19.1.0 - XML External Entity (XXE)Network Scanner

High(7.5)

No
Cybersecurity Infrastructure Security Agency (CISA)SysAid On-Prem <= 23.3.40 - XML External EntityNetwork Scanner

Critical(9.3)

No
Cybersecurity Infrastructure Security Agency (CISA)SysAid On-Prem <= 23.3.40 - XML External EntityNetwork Scanner

Critical(9.3)

No
SysAid On-Prem <= 23.3.40 - XML External EntityNetwork Scanner

Critical(9.3)

No
Generic XML External Entity - (XXE)Network Scanner

Medium

No
EcologyOA deleteUserRequestInfoByXml - XML External Entity InjectionNetwork Scanner

High

No
Wanhu OA TeleConferenceService Interface - XML External Entity InjectionNetwork Scanner

High

No
74CMS weixin.php - SQL InjectionNetwork Scanner

High

No
Ivanti Avalanche SmartDeviceServer - XML External EntityNetwork Scanner

High(7.5)

No
Cybersecurity Infrastructure Security Agency (CISA)Magento - XML External Entity InjectionNetwork Scanner

Critical(9.8)

Yes
Cybersecurity Infrastructure Security Agency (CISA)Adobe Commerce & Magento - CosmicStingNetwork Scanner

Critical(9.8)

No
OpenCMS - XML external entity (XXE)Network Scanner

High(9.8)

No
Ivanti Connect Secure - XXENetwork Scanner

High(8.3)

No
FreeIPA - XML Entity InjectionNetwork Scanner

High(7.5)

No