CVE-2018-9116: Wiremock

Critical severity, CVSS 9.1. EPSS: 1.9% chance of exploitation in the next 30 days.

An XXE vulnerability within WireMock before 2.16.0 allows a remote unauthenticated attacker to access local files and internal resources and potentially cause a Denial of Service.

Affected products

  • Wiremock Wiremock: before 2.16.0 (fixed in 2.16.0)

Published 2018-03-29. Last modified 2026-06-17.