CWE-91

XML Injection (aka Blind XPath Injection)

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system.

116 vulnerabilities with CWE-91
CVE-2022-22784 HIGH
Zoom Client <5.10.0 - Code Injection
CVSS 8.1
CVE-2022-20729 MEDIUM
Cisco Firepower Threat Defense - Command Injection
CVSS 4.4
CVE-2022-25356 MEDIUM
Alt-N MDaemon Security Gateway <8.5.0 - XML Injection
CVSS 5.3
CVE-2022-22834 HIGH
Overit Geocall < 8.0 - Remote Code Execution
CVSS 8.8
CVE-2021-4140 CRITICAL
Firefox ESR < 91.5, Firefox < 96, Thunderbird < 91.5 - XSS
CVSS 10.0
CVE-2021-27777 HIGH
XML Parser - XXE Injection
CVSS 7.5
CVE-2021-38948 CRITICAL
IBM InfoSphere Information Server 11.7 - XXE
CVSS 9.1
CVE-2021-22524 MEDIUM
NetIQ Access Manager <5.0.1, 4.5.4 - DoS
CVSS 5.4
CVE-2021-39181 HIGH
OpenOlat <15.3.18, <15.5.3, <16.0.0 - Code Injection
CVSS 8.8
CVE-2021-36033 CRITICAL
Magento Commerce <2.4.2-2.3.7 - Code Injection
CVSS 9.1
CVE-2021-36028 CRITICAL
Magento Commerce <2.4.2-2.3.7 - Code Injection
CVSS 9.1
CVE-2021-36022 CRITICAL
Magento Commerce <2.4.2-2.3.7 - Code Injection
CVSS 9.1
CVE-2021-36020 HIGH
Magento Commerce <2.4.2-2.3.7 - Code Injection
CVSS 8.2
CVE-2021-36359 HIGH
OrbiTeam BSCW Classic <7.4.3 - Authenticated RCE
CVSS 8.8
CVE-2021-32758 HIGH
OpenMage Magento LTS <19.4.15, <20.0.11 - Command Injection
CVSS 7.2
CVE-2021-37154 CRITICAL
ForgeRock AM <7.0.2 - Code Injection
CVSS 9.8
CVE-2021-32796 MEDIUM
xmldom <0.7.0 - Info Disclosure
CVSS 6.5
CVE-2021-2322 HIGH
OpenGrok <1.6.7 - RCE
CVSS 8.8
CVE-2021-31347 MEDIUM
libezxml.a <0.8.6 - Memory Corruption
CVSS 6.5
CVE-2021-21025 CRITICAL
Magento <2.4.1-2.3.6 - Code Injection
CVSS 9.1
CVE-2021-21019 CRITICAL
Magento <2.4.1-2.3.6 - Code Injection
CVSS 9.1
CVE-2020-29599 HIGH
ImageMagick <7.0.10-40 - Command Injection
CVSS 7.8
CVE-2020-29128 CRITICAL
petl <1.68 - Info Disclosure
CVSS 9.8
CVE-2020-4774 MEDIUM
IBM Curam Social Program Management <7.0.10 - Info Disclosure
CVSS 5.4
CVE-2020-25216 CRITICAL
yWorks yEd Desktop <3.20.1 - Code Injection
CVSS 9.8
Details
Vulnerabilities 116