CWE-91

XML Injection (aka Blind XPath Injection)

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system.

116 vulnerabilities with CWE-91
CVE-2026-32870 HIGH
Kirby has XML injection in its XML creator toolkit
CVSS 7.5
CVE-2026-34601 HIGH
xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion
CVSS 7.5
CVE-2026-28770 HIGH
IDC SFX Series 101 - XML Injection
CVSS 8.8
CVE-2026-1554 MEDIUM
Jtenman Central Authentication System Server - Privilege Escalation
CVSS 4.2
CVE-2025-1545 HIGH
WatchGuard Fireware OS <12.11.4-12.5.13 - Info Disclosure
CVSS 7.5
CVE-2025-66034 MEDIUM
fontTools <4.60.2 - RCE
CVSS 6.3
CVE-2025-12921 MEDIUM
OpenClinica Community Edition <3.12.2/3.13 - XML Injection
CVSS 4.3
CVE-2025-7473 MEDIUM
Zohocorp ManageEngine EndPoint Central <11.4.2516.1 - XML Injection
CVSS 5.2
CVE-2025-60833 MEDIUM
uzy-ssm-mall <v1.1.0 - XSS
CVSS 6.5
CVE-2025-54251 MEDIUM
Adobe Experience Manager <6.5.23.0 - Code Injection
CVSS 4.3
CVE-2025-24404 HIGH
Apache HertzBeat <1.7.0 - RCE
CVSS 8.8
CVE-2025-9375 MEDIUM
xmltodict <0.15.1 - XML Injection
CVE-2025-47184 MEDIUM
Exagid EX10 <6.4.0 P20-7.2.0 P08 - SSRF
CVSS 5.3
CVE-2025-49538 HIGH
Adobe Coldfusion - Denial of Service
CVSS 7.4
CVE-2025-25589 HIGH
yimioa <2024.07.04 - RCE
CVSS 8.1
CVE-2024-47113 HIGH
IBM ICP - Voice Gateway <1.0.8 - RCE
CVSS 8.1
CVE-2024-13190 MEDIUM
ZeroWdd myblog 1.0 - XML Injection
CVSS 6.3
CVE-2024-53675 HIGH
HPE Insight Remote Support < 7.14.0.629 - XXE
CVSS 7.3
CVE-2024-53674 HIGH
HPE Insight Remote Support < 7.14.0.629 - XXE
CVSS 7.3
CVE-2024-11622 HIGH
HPE Insight Remote Support - Info Disclosure
CVSS 7.3
CVE-2024-51136 CRITICAL
Openimaj - XXE
CVSS 9.8
CVE-2024-34740 HIGH
Google Android - Integer Overflow
CVSS 7.8
CVE-2024-42374 HIGH
BEx Web Java Runtime Export Web Service - Info Disclosure
CVSS 8.2
CVE-2024-33858 MEDIUM
Logpoint <7.4.0 - Path Injection
CVSS 5.3
CVE-2024-28109 HIGH
Org.verapdf Core < 1.24.2 - Remote Code Execution
CVSS 8.1
Details
Vulnerabilities 116