LiveActive security incident?Get immediate response
CWE Reference

CWE for xml

Browse cwe for xml with official CWE context and Glexia analysis.

Release 4.20listing

Search And Filters

Browse CWE records

Showing 3 of 3 CWE records.

CWE-827WeaknessVariant

CWE-827: Improper Control of Document Type Definition

The product does not restrict a reference to a Document Type Definition (DTD) to the intended control sphere. This might allow attackers to reference arbitrary DTDs, possibly causing the product to expose files, consume excessive system resources, or execute arbitrary http requests on behalf of the attacker.