CVE-2026-19614
XML External Entity (XXE) Injection in CyberELF NanoXML
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The API is prone to XML external entity (XXE) injection. By default, XML external entity support is enabled. This issue affects NanoXML: 2.2.3.
| CWE | CWE-611 |
| Vendor | cyberelf |
| Product | nanoxml |
| Published | Sep 8, 2026 |
| Last Updated | Sep 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for cyberelf nanoxml
Be the first to know when new unknown vulnerabilities affecting cyberelf nanoxml are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
CyberELF / NanoXML
2.2.3
References
Credits
Dominique RIGHETTO