CVE-2019-13608: Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability
High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 30% chance of exploitation in the next 30 days.
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.
Affected products
- Citrix StoreFront Server: from 1811, before 1903 (fixed in 1903); before 3.12.4000 (fixed in 3.12.4000); before 3.0.8000 (fixed in 3.0.8000)
Published 2019-08-29. Last modified 2026-06-17.