CWE-91

XML Injection (aka Blind XPath Injection)

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system.

114 vulnerabilities with CWE-91
CVE-2026-28770
IDC SFX Series 101 - XML Injection
CVE-2026-1554 MEDIUM
Jtenman Central Authentication System Server - Privilege Escalation
CVSS 4.2
CVE-2022-50902 HIGH
Wondershare FamiSafe 1.0 - Code Injection
CVSS 8.4
CVE-2025-1545 HIGH
WatchGuard Fireware OS <12.11.4-12.5.13 - Info Disclosure
CVSS 7.5
CVE-2025-66034 MEDIUM
fontTools <4.60.2 - RCE
CVSS 6.3
CVE-2025-12921 MEDIUM
OpenClinica Community Edition <3.12.2/3.13 - XML Injection
CVSS 4.3
CVE-2025-7473 MEDIUM
Zohocorp ManageEngine EndPoint Central <11.4.2516.1 - XML Injection
CVSS 5.2
CVE-2025-60833 MEDIUM
uzy-ssm-mall <v1.1.0 - XSS
CVSS 6.5
CVE-2025-54251 MEDIUM
Adobe Experience Manager <6.5.23.0 - Code Injection
CVSS 4.3
CVE-2025-24404 HIGH
Apache HertzBeat <1.7.0 - RCE
CVSS 8.8
CVE-2025-9375
xmltodict <0.15.1 - XML Injection
CVE-2025-47184 MEDIUM
Exagid EX10 <6.4.0 P20-7.2.0 P08 - SSRF
CVSS 5.3
CVE-2025-49538 HIGH
Adobe Coldfusion - Denial of Service
CVSS 7.4
CVE-2025-25589 HIGH
yimioa <2024.07.04 - RCE
CVSS 8.1
CVE-2024-47113 HIGH
IBM ICP - Voice Gateway <1.0.8 - RCE
CVSS 8.1
CVE-2024-13190 MEDIUM
ZeroWdd myblog 1.0 - XML Injection
CVSS 6.3
CVE-2024-53675 HIGH
HPE Insight Remote Support < 7.14.0.629 - XXE
CVSS 7.3
CVE-2024-53674 HIGH
HPE Insight Remote Support < 7.14.0.629 - XXE
CVSS 7.3
CVE-2024-11622 HIGH
HPE Insight Remote Support - Info Disclosure
CVSS 7.3
CVE-2024-51136 CRITICAL
Openimaj - XXE
CVSS 9.8
CVE-2024-34740 HIGH
Google Android - Integer Overflow
CVSS 7.8
CVE-2024-42374 HIGH
BEx Web Java Runtime Export Web Service - Info Disclosure
CVSS 8.2
CVE-2023-35858 MEDIUM
Modern Campus - Omni CMS 2023.1 - Info Disclosure
CVSS 5.3
CVE-2024-33858 MEDIUM
Logpoint <7.4.0 - Path Injection
CVSS 5.3
CVE-2023-32173 MEDIUM
Unified Automation UaGateway - XML Injection DoS
CVSS 5.8
Details
Vulnerabilities 114