CWE-91— XML Injection
The product does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system.— MITRE CWE catalog
156 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-91page 3 of 4
- CVE-2017-1000452HIGHCVSS 7.5EG 7.52018-01-02
An XML Signature Wrapping vulnerability exists in Samlify 2.2.0 and earlier, and in predecessor Express-saml2 which could allow attackers to impersonate arbitrary users.
- CVE-2017-5654HIGHCVSS 7.5EG 7.52017-05-12
In Ambari 2.4.x (before 2.4.3) and Ambari 2.5.0, an authorized user of the Ambari Hive View may be able to gain unauthorized read access to files on the host where the Ambari server executes.
- CVE-2016-5697HIGHCVSS 7.5EG 7.52017-01-23
Ruby-saml before 1.3.0 allows attackers to perform XML signature wrapping attacks via unspecified vectors.
- CVE-2022-27233HIGHCVSS 6.5EG 7.52022-11-11
XML injection in the Quartus(R) Prime Programmer included in the Intel(R) Quartus Prime Pro and Standard edition software may allow an unauthenticated user to potentially enable information disclosure via network access.
- CVE-2008-5024HIGHCVSS v2 7.5EG 7.52008-11-13
Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML i…
- CVE-2025-49538HIGHCVSS 7.4EG 7.42025-07-08
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an XML Injection vulnerability that could lead to arbitrary file system read. An attacker can exploit this issue by injecting crafted XML or XPath queries to access u…
- CVE-2024-11622HIGHCVSS 7.3EG 7.32024-11-26
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.
- CVE-2026-102116HIGHCVSS 7.2EG 7.22026-09-30
-A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to write a file outside its intended location and cause the application to execute it, potentially resulting in remote code execution as the u…
- CVE-2019-25137HIGHCVSS 7.2EG 7.22023-05-18
Umbraco CMS 4.11.8 through 7.15.10, and 7.12.4, allows Remote Code Execution by authenticated administrators via msxsl:script in an xsltSelection to developer/Xslt/xsltVisualize.aspx.
- CVE-2022-34253HIGHCVSS 7.2EG 7.22022-08-16
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an XML Injection vulnerability in the Widgets Module. An attacker with admin privileges can trigger a specially crafted script t…
- CVE-2021-32758HIGHCVSS 7.2EG 7.22021-08-27
OpenMage Magento LTS is an alternative to the Magento CE official releases. Prior to versions 19.4.15 and 20.0.11, layout XML enabled admin users to execute arbitrary commands via block methods. The latest OpenMage Versions up from v19.4.1…
- CVE-2018-16784HIGHCVSS 7.2EG 7.22018-09-21
DedeCMS 5.7 SP2 allows XML injection, and resultant remote code execution, via a "<file type='file' name='../" substring.
- CVE-2019-4539HIGHCVSS 7.1EG 7.12019-10-02
IBM Security Directory Server 6.4.0 does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system. IBM X-Force ID: 16581…
- CVE-2025-9375MEDIUMCVSS 6.9EG 6.92025-09-01
XML Injection vulnerability in xmltodict allows Input Data Manipulation. This issue affects xmltodict: from 0.14.2 before 0.15.1. NOTE: the scope of this CVE is disputed by the vendor on the grounds that xmltodict.unparse() delegates elem…
- CVE-2026-47273MEDIUMCVSS 6.5EG 6.52026-05-27
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, pam_usb builds XPath expressions from user-supplied identifiers (PAM username, service name) and device-supplied identifiers (USB device ser…
- CVE-2025-60833MEDIUMCVSS 6.5EG 6.52025-10-08
An XML External Entity (XXE) vulnerability in the /mall/wxpay/pay component of uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying crafted XML data.
- CVE-2023-29289MEDIUMCVSS 6.5EG 6.52023-06-15
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an XML Injection vulnerability. An attacker with low privileges can trigger a specially crafted script to a security feature byp…
- CVE-2021-32796MEDIUMCVSS 6.5EG 6.52021-07-27
xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.6.0 and older do not correctly escape special characters when serializing elements removed from their …
- CVE-2021-31348MEDIUMCVSS 6.5EG 6.52021-04-16
An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling while parsing crafted XML files (out-of-bounds read after a certain strcspn failure).
- CVE-2021-31347MEDIUMCVSS 6.5EG 6.52021-04-16
An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling while parsing crafted XML files (writing outside a memory region created by mmap).
- CVE-2019-20201MEDIUMCVSS 6.5EG 6.52019-12-31
An issue was discovered in ezXML 0.8.3 through 0.8.6. The ezxml_parse_* functions mishandle XML entities, leading to an infinite loop in which memory allocations occur.
- CVE-2019-0370MEDIUMCVSS 6.5EG 6.52019-10-08
Due to missing input validation, SAP Financial Consolidation, before versions 10.0 and 10.1, enables an attacker to use crafted input to interfere with the structure of the surrounding query leading to XPath Injection.
- CVE-2019-9892MEDIUMCVSS 6.5EG 6.52019-05-22
An issue was discovered in Open Ticket Request System (OTRS) 5.x through 5.0.34, 6.x through 6.0.17, and 7.x through 7.0.6. An attacker who is logged into OTRS as an agent user with appropriate permissions may try to import carefully craft…
- CVE-2024-13190MEDIUMCVSS 6.3EG 6.32025-01-08
A vulnerability classified as critical was found in ZeroWdd myblog 1.0. This vulnerability affects unknown code of the file src/main/resources/mapper/BlogMapper.xml. The manipulation of the argument findBlogList/getTotalBlogs leads to xml …
- CVE-2026-89247MEDIUMCVSS 6.1EG 6.12026-09-11
WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier contains an XML injection vulnerability in plugin/AD_Server/VMAP.php, which is reachable without authentication when the AD_Server plugin is enabled. The script emi…
- CVE-2026-44665MEDIUMCVSS 6.1EG 6.12026-05-13
fast-xml-builder builds XML from JSON. Prior to 1.1.7, when an input data has quotes in attribute values but process entities is not enabled, it breaks the attribute value into multiple attributes. This gives the room for an attacker to in…
- CVE-2026-44664MEDIUMCVSS 6.1EG 6.12026-05-13
fast-xml-builder builds XML from JSON. In 1.1.5, the fix for CVE-2026-41650 in fast-xml-parser sanitizes -- sequences in XML comment content using .replace(/--/g, '- -'). This skip the values containing three consecutive dashes (e.g., --->…
- CVE-2026-41650MEDIUMCVSS 6.1EG 6.12026-05-07
fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Prior to version 5.7.0, XMLBuilder does not escape the "-->" sequence in comment content or the "]]>" sequence in CDATA sections when bu…
- CVE-2017-2171MEDIUMCVSS 6.1EG 6.12017-05-22
Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admi…
- CVE-2026-53723MEDIUMCVSS 5.8EG 5.82026-06-11
Guzzle Services provides an implementation of the Guzzle Command library that uses Guzzle service descriptions to describe web services, serialize requests, and parse responses into easy to use model structures. Versions prior ro 1.5.4 do …
- CVE-2023-32173MEDIUMCVSS 5.8EG 5.82024-05-03
Unified Automation UaGateway AddServer XML Injection Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation UaGateway. Authenticat…
- CVE-2022-32755MEDIUMCVSS 5.5EG 5.52023-10-14
IBM Security Directory Server 6.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. I…
- CVE-2026-27693MEDIUMCVSS 5.4EG 5.42026-05-05
Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the KML and GPX export functionality writes device names to XML output without proper escaping. An attacker with low privilege…
- CVE-2021-22524MEDIUMCVSS 5.4EG 5.42021-09-13
Injection attack caused the denial of service vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4
- CVE-2020-4774MEDIUMCVSS 5.4EG 5.42020-10-12
An XPath vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, caused by the improper handling of user-supplied input. By sending a specially-crafted input, a remote attacker could exploit this vulnerability to obt…
- CVE-2025-7473MEDIUMCVSS 5.3EG 5.32025-10-21
Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection.
- CVE-2025-47184MEDIUMCVSS 5.3EG 5.32025-08-21
An XML external entities (XXE) injection vulnerability in the /init API endpoint in Exagid EX10 before 6.4.0 P20, 7.0.1 P12, and 7.2.0 P08 allows an authenticated, unprivileged attacker to achieve information disclosure and privilege escal…
- CVE-2023-35858MEDIUMCVSS 5.3EG 5.32024-06-13
XPath Injection vulnerabilities in the blog and RSS functions of Modern Campus - Omni CMS 2023.1 allow a remote, unauthenticated attacker to obtain application information.
- CVE-2024-33858MEDIUMCVSS 5.3EG 5.32024-05-07
An issue was discovered in Logpoint before 7.4.0. A path injection vulnerability is seen while adding a CSV enrichment source. The source_name parameter could be changed to an absolute path; this will write the CSV file to that path inside…
- CVE-2023-40612MEDIUMCVSS 5.3EG 5.32023-08-23
In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2, the file editor which is accessible to any user with ROLE_FILESYSTEM_EDITOR privileges is vulnerable to XXE injection attacks. The solution is to upgrade to Meridian 2023.1.5 or H…
- CVE-2023-22485MEDIUMCVSS 5.3EG 5.32023-01-24
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior 0.29.0.gfm.7, a crafted markdown document can trigger an out-of-bounds read in the `validate_protocol` function. We believe…
- CVE-2022-22244MEDIUMCVSS 5.3EG 5.32022-10-18
An XPath Injection vulnerability in the J-Web component of Juniper Networks Junos OS allows an unauthenticated attacker sending a crafted POST to reach the XPath channel, which may allow chaining to other unspecified vulnerabilities, leadi…
- CVE-2022-25356MEDIUMCVSS 5.3EG 5.32022-04-05
Alt-N MDaemon Security Gateway through 8.5.0 allows SecurityGateway.dll?view=login XML Injection.
- CVE-2020-6260MEDIUMCVSS 5.3EG 5.32020-06-10
SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to inject superflous data that can be displayed by the application, due to Incomplete XML Validation. The application shows additional data that do not actually exist.
- CVE-2016-2932MEDIUMCVSS 5.3EG 5.32016-11-30
IBM BigFix Remote Control before 9.1.3 allows remote attackers to conduct XML injection attacks via unspecified vectors.
- CVE-2026-24329MEDIUMCVSS 4.9EG 4.92026-08-11
A flaw was found in wildfly-core. A remote user authenticated as an administrative user can inject a malformed payload into the Inet Address field through the Management Model. This injection causes the server to crash and become unrecover…
- CVE-2026-59728MEDIUMCVSS 4.3EG 4.32026-07-20
Astro is a web framework for content-driven websites. In versions 1.0.0 through 4.0.18, the source.title and enclosure.type item fields in packages/astro-rss/src/index.ts are interpolated directly into XML template strings without XML-char…
- CVE-2025-54251MEDIUMCVSS 4.3EG 4.32025-09-09
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an XML Injection vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to manipulate XML queries and…
- CVE-2024-2648MEDIUMCVSS 4.3EG 4.32024-03-19
A vulnerability, which was classified as problematic, was found in Netentsec NS-ASG Application Security Gateway 6.3. Affected is an unknown function of the file /nac/naccheck.php. The manipulation of the argument username leads to imprope…
- CVE-2024-2645MEDIUMCVSS 4.3EG 4.32024-03-19
A vulnerability classified as problematic has been found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /vpnweb/resetpwd/resetpwd.php. The manipulation of the argument UserId leads to imprope…
Map vulnerabilities like CWE-91 to your infrastructure
EchelonGraph correlates every CVE — across CWE-91 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →