CWE-91

XML Injection (aka Blind XPath Injection)

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system.

128 vulnerabilities with CWE-91
CVE-2025-49538 HIGH
ColdFusion <= 2025.2, <= 2023.14, <= 2021.20 - XML Injection via Crafted XML or XPath Queries
CVSS 7.4
CVE-2025-25589 HIGH
yimioa < v2024.07.04 - XML External Entity Injection in XMLParse.java
CVSS 8.1
CVE-2024-47113 HIGH
IBM ICP - Voice Gateway <1.0.8 - RCE
CVSS 8.1
CVE-2024-13190 MEDIUM
ZeroWdd myblog 1.0 - XML Injection via BlogMapper.xml findBlogList/getTotalBlogs Argument
CVSS 6.3
CVE-2024-53675 HIGH
HPE Insight Remote Support < 7.14.0.629 - XML External Entity Injection
CVSS 7.3
CVE-2024-53674 HIGH
HPE Insight Remote Support < 7.14.0.629 - XML External Entity Injection
CVSS 7.3
CVE-2024-11622 HIGH
HPE Insight Remote Support - Info Disclosure
CVSS 7.3
CVE-2024-51136 CRITICAL
OpenIMAJ Dmoz2CSV - XML External Entity Injection
CVSS 9.8
CVE-2024-34740 HIGH
Android - Integer Overflow in BinaryXmlSerializer
CVSS 7.8
CVE-2024-42374 HIGH
BEx Web Java Runtime Export Web Service - Info Disclosure
CVSS 8.2
CVE-2024-33858 MEDIUM
Logpoint SIEM < 7.4.0 - Path Traversal and Arbitrary File Write via CSV Enrichment Source
CVSS 5.3
CVE-2024-28109 HIGH
veraPDF-library < 1.24.2 - Remote Code Execution via Custom Schematron XSL Transformation
CVSS 8.1
CVE-2024-2648 MEDIUM
Netentsec NS-ASG 6.3 - Improper Neutralization of Data within XPath...
CVSS 4.3
CVE-2024-2645 MEDIUM
Netentsec NS-ASG Application Security Gateway 6.3 - XPath Injection
CVSS 4.3
CVE-2024-25413 HIGH
FireBear Improved Import And Export <3.8.6 - SSRF
CVSS 7.2
CVE-2023-35858 MEDIUM
Modern Campus - Omni CMS 2023.1 - Info Disclosure
CVSS 5.3
CVE-2023-32173 MEDIUM
Unified Automation UaGateway - XML Injection DoS
CVSS 5.8
CVE-2023-27328 HIGH
Parallels Desktop < 18.1.1 (53328) - Local Privilege Escalation via Toolgate XML Injection
CVSS 7.8
CVE-2023-46214 HIGH
Splunk Enterprise <9.0.7-9.1.2 - RCE
CVSS 8.0
CVE-2023-43187 CRITICAL
NodeBB < 1.18.6 - Remote Code Execution via XML-RPC Request
CVSS 9.8
CVE-2023-40612 MEDIUM
OpenMNS Horizon <32.0.2 - XXE Injection
CVSS 5.3
CVE-2023-38207 HIGH
Adobe Commerce <2.4.6-p1, <2.4.5-p3, <2.4.4-p4 - XML Injection
CVSS 7.5
CVE-2023-29289 MEDIUM
Adobe Commerce <2.4.6 - XML Injection
CVSS 6.5
CVE-2023-22247 HIGH
Adobe Commerce <2.4.4-p2, 2.4.5-p1 - XML Injection
CVSS 7.5
CVE-2023-27253 HIGH
Netgate pfSense <2.7.0 - Command Injection
CVSS 8.8
Details
Vulnerabilities 128