Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 16.073 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 177 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Search results for: XML External Entity

Displaying 1 - 25 results out of 63

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
GeoServer - XML External Entity InjectionNetwork Scanner

High(8.2)

No
Guralp MAN-EAM-0003 3.2.4 - XML External Entity (XXE)Network Scanner

High(7.5)

No
Apache Tika 1.13 - 3.2.1 XXE VulnerabilityNetwork Scanner

Critical(9.8)

No
Akamai CloudTest < 60 2025.06.02 - XML External Entity (XXE)Network Scanner

Critical(9.1)

No
GeoServer WFS - XXE Processing VulnerabilityNetwork Scanner

Critical(9.9)

No
LabKey Server 19.1.0 - XML External Entity (XXE)Network Scanner

High(7.5)

No
Cybersecurity Infrastructure Security Agency (CISA)SysAid On-Prem <= 23.3.40 - XML External EntityNetwork Scanner

Critical(9.3)

No
SysAid On-Prem <= 23.3.40 - XML External EntityNetwork Scanner

Critical(9.3)

No
Cybersecurity Infrastructure Security Agency (CISA)SysAid On-Prem <= 23.3.40 - XML External EntityNetwork Scanner

Critical(9.3)

No
74CMS weixin.php - SQL InjectionNetwork Scanner

High

No
Wanhu OA TeleConferenceService Interface - XML External Entity InjectionNetwork Scanner

High

No
Generic XML External Entity - (XXE)Network Scanner

Medium

No
EcologyOA deleteUserRequestInfoByXml - XML External Entity InjectionNetwork Scanner

High

No
Ivanti Avalanche SmartDeviceServer - XML External EntityNetwork Scanner

High(7.5)

No
Cybersecurity Infrastructure Security Agency (CISA)Magento - XML External Entity InjectionNetwork Scanner

Critical(9.8)

Yes
Cybersecurity Infrastructure Security Agency (CISA)Adobe Commerce & Magento - CosmicStingNetwork Scanner

Critical(9.8)

No
OpenCMS - XML external entity (XXE)Network Scanner

High(9.8)

No
Ivanti Connect Secure - XXENetwork Scanner

High(8.3)

No
FreeIPA - XML Entity InjectionNetwork Scanner

High(7.5)

No
Cybersecurity Infrastructure Security Agency (CISA)Oracle Business Intelligence/XML Publisher - XML External Entity InjectionNetwork Scanner

High(7.2)

No
Oracle Business Intelligence Publisher - XML External Entity InjectionNetwork Scanner

High(7.2)

No
SAP Internet Graphics Server (IGS) - XML External Entity InjectionNetwork Scanner

High(7.5)

No
Adobe Experience Manager - XML External Entity InjectionNetwork Scanner

High(7.5)

No
Zoho ManageEngine ADAudit Plus <7600 - XML Entity Injection/Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
LumisXP <10.0.0 - Blind XML External Entity AttackNetwork Scanner

Critical(9.1)

No