{"id":"CVE-2018-1000069","details":"FreePlane version 1.5.9 and earlier contains a XML External Entity (XXE) vulnerability in XML Parser in mindmap loader that can result in stealing data from victim's machine. This attack appears to require the victim to open a specially crafted mind map file. This vulnerability appears to have been fixed in 1.6+.","modified":"2026-04-16T06:25:56.500267392Z","published":"2018-03-13T15:29:00.207Z","references":[{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2018/03/msg00019.html"},{"type":"ADVISORY","url":"https://www.debian.org/security/2018/dsa-4175"},{"type":"ADVISORY","url":"https://www.freeplane.org/wiki/index.php/XML_External_Entity_vulnerability_in_map_parser"},{"type":"EVIDENCE","url":"https://www.youtube.com/watch?v=7IXtiTNilAI"}],"affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1000069.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"1.5.9"}]},{"events":[{"introduced":"0"},{"last_affected":"7.0"}]},{"events":[{"introduced":"0"},{"last_affected":"8.0"}]},{"events":[{"introduced":"0"},{"last_affected":"9.0"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"}]}