CWE-91

XML Injection (aka Blind XPath Injection)

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system.

116 vulnerabilities with CWE-91
CVE-2024-2648 MEDIUM
Netentsec NS-ASG 6.3 - Improper Neutralization of Data within XPath...
CVSS 4.3
CVE-2024-2645 MEDIUM
Netentsec NS-ASG Application Security Gateway 6.3 - XPath Injection
CVSS 4.3
CVE-2024-25413 HIGH
FireBear Improved Import And Export <3.8.6 - SSRF
CVSS 7.2
CVE-2023-35858 MEDIUM
Modern Campus - Omni CMS 2023.1 - Info Disclosure
CVSS 5.3
CVE-2023-32173 MEDIUM
Unified Automation UaGateway - XML Injection DoS
CVSS 5.8
CVE-2023-27328 HIGH
Parallels Desktop < 18.1.1_\(53328\) - Privilege Escalation
CVSS 7.8
CVE-2023-46214 HIGH
Splunk Enterprise <9.0.7-9.1.2 - RCE
CVSS 8.0
CVE-2023-43187 CRITICAL
NodeBB <1.18.6 - RCE
CVSS 9.8
CVE-2023-40612 MEDIUM
OpenMNS Horizon <32.0.2 - XXE Injection
CVSS 5.3
CVE-2023-38207 HIGH
Adobe Commerce <2.4.6-p1, <2.4.5-p3, <2.4.4-p4 - XML Injection
CVSS 7.5
CVE-2023-29289 MEDIUM
Adobe Commerce <2.4.6 - XML Injection
CVSS 6.5
CVE-2023-22247 HIGH
Adobe Commerce <2.4.4-p2, 2.4.5-p1 - XML Injection
CVSS 7.5
CVE-2023-27253 HIGH
Netgate pfSense <2.7.0 - Command Injection
CVSS 8.8
CVE-2023-22485 MEDIUM
Github Cmark-gfm < 0.29.0.gfm.7 - Out-of-Bounds Access
CVSS 5.3
CVE-2022-50902 HIGH
Wondershare FamiSafe 1.0 - Code Injection
CVSS 8.4
CVE-2022-32755 MEDIUM
IBM Security Directory Server - XXE
CVSS 5.5
CVE-2022-4245 MEDIUM
Codehaus-plexus Plexus-utils < 3.0.24 - XXE
CVSS 4.3
CVE-2022-46751 HIGH
Apache Ivy <2.5.2 - XML Injection
CVSS 8.2
CVE-2022-35259 HIGH
Endpoint Manager <2022.3 - Code Injection
CVSS 7.8
CVE-2022-27233 MEDIUM
Intel Quartus Prime < 21.1 - Information Disclosure
CVSS 6.5
CVE-2022-22244 MEDIUM
Juniper Networks Junos OS <19.1R3-S9, <19.2R3-S6, <19.3R3-S7, <19.4...
CVSS 5.3
CVE-2022-22243 MEDIUM
Juniper Networks Junos OS <19.1R3-S9-20 - XPath Injection
CVSS 4.3
CVE-2022-34253 HIGH
Adobe Commerce <2.4.3-p2, 2.3.7-p3, 2.4.4 - Code Injection
CVSS 7.2
CVE-2022-2458 HIGH
Redhat Process Automation Manager < 7.13.1 - XXE
CVSS 8.2
CVE-2022-33739 HIGH
CA Clarity <15.9.0 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 116