SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on.
{ "nvd_published_at": "2017-11-17T21:29:00Z", "github_reviewed_at": "2022-05-31T17:18:38Z", "severity": "CRITICAL", "github_reviewed": true, "cwe_ids": [ "CWE-611" ] }