CWE-91
XML Injection (aka Blind XPath Injection)
The product does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system.
128 vulnerabilities with CWE-91
CVE-2019-14277
CRITICAL
Axway SecureTransport <5.3-5.5 - Unauthenticated XXE
CVSS 9.8
CVE-2019-1010017
HIGH
libnmap < 0.6.3 - Denial of Service via XML Injection
CVSS 7.5
CVE-2019-9892
MEDIUM
OTRS <5.0.34, <6.0.17, <7.0.6 - Info Disclosure
CVSS 6.5
CVE-2019-0268
HIGH
SAP BusinessObjects <4.30 - Info Disclosure
CVSS 8.1
CVE-2018-1721
HIGH
IBM Cognos Analytics 11.0 and 11.1 - XML External Entity Injection
CVSS 8.8
CVE-2018-19277
HIGH
PHPOffice PhpSpreadsheet <1.5.0 - XSS
CVSS 8.8
CVE-2018-2477
HIGH
SAP NetWeaver <7.51 - Info Disclosure
CVSS 8.8
CVE-2018-16784
HIGH
DedeCMS 5.7 SP2 - Remote Code Execution via XML Injection
CVSS 7.2
CVE-2018-16785
HIGH
dedecms V5.7 SP2 - XML Injection
CVSS 8.8
CVE-2018-1000632
HIGH
dom4j 2.0.0-2.0.3 - XML Injection via Element.addElement or Element.addAttribute
CVSS 7.5
CVE-2018-1000526
HIGH
openpsa - XML Injection via RSS File Upload
CVSS 7.5
CVE-2017-15685
HIGH
Crafter CMS Crafter Studio 3.0.1 - Unauthenticated XML External Entity Injection
CVSS 8.6
CVE-2017-15683
HIGH
Crafter CMS Crafter Studio <3.0.1 - Info Disclosure
CVSS 8.6
CVE-2017-1000452
HIGH
Samlify < 2.2.0 - XML Signature Wrapping
CVSS 7.5
CVE-2017-10603
HIGH
Junos OS <15.1X53-D47-15.1R3 - Privilege Escalation
CVSS 7.0
CVE-2017-2171
MEDIUM
BestWebSoft Plugins - Cross-Site Scripting via BestWebSoft Menu Function
CVSS 6.1
CVE-2017-5654
HIGH
Ambari <2.4.3-2.5.0 - Info Disclosure
CVSS 7.5
CVE-2016-6272
HIGH
Epic MyChart - XPath Injection via Help Topic Parameter
CVSS 7.5
CVE-2016-5697
HIGH
ruby-saml < 1.3.0 - XML Signature Wrapping Attack
CVSS 7.5
CVE-2016-2932
MEDIUM
IBM BigFix Remote Control <9.1.3 - Code Injection
CVSS 5.3
CVE-2015-6970
CRITICAL
Bosch Security Systems NBN-498 Dinion2X - XML Injection
CVSS 9.8
CVE-2015-3932
HIGH
Netlock Mokka < 2.7 - XML Signature Wrapping via Crafted ds:Object Node
CVSS 7.8
CVE-2015-3931
HIGH
Microsec e-Szigno <3.2.7.12 - Code Injection
CVSS 7.8
CVE-2014-1409
CRITICAL
MobileIron Virtual Smartphone Platform < 5.9.1 and Sentry < 5.0 - Authentication Bypass via XML Password Obfuscation
CVSS 9.1
CVE-2013-4857
CRITICAL
D-Link DIR-865L Firmware - PHP File Inclusion via Router XML File
CVSS 9.8
Details
Vulnerabilities
128