WXPayUtil in WeChat Pay Java SDK allows XXE attacks involving a merchant notification URL.
CVSS Metrics