CVE-2019-20191: Sync Oxygen XML Author

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

Oxygen XML Editor 21.1.1 allows XXE to read any file.

Affected products

  • Sync Oxygen XML Author: up to and including 21.1
  • Sync Oxygen XML Developer: up to and including 21.1
  • Sync Oxygen XML Editor: up to and including 21.1.1

Published 2020-03-16. Last modified 2026-06-17.