Skip to content
Noroxi

CWE-91 · 135 records

XML Injection (aka Blind XPath Injection)

CVEs in this class

135 records

  • A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    microsoft · .net frameworkJan 14, 2020

  • CVE-2023-27253
    62This week

    A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbi

    HighCVSS 8.8WeaponizedEPSS 90%

    netgate · pfsenseMar 17, 2023

  • CVE-2023-46214
    62This week

    Remote code execution (RCE) in Splunk Enterprise through Insecure XML Parsing

    HighCVSS 8.8WeaponizedEPSS 89%

    splunk · cloudNov 16, 2023

  • An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain

    HighCVSS 7.5No exploitEPSS 84%

    hpe · insight remote supportNov 26, 2024

  • A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers

    CriticalCVSS 9.8Proof of conceptEPSS 47%

    nodebb · nodebbSep 27, 2023

  • An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain

    HighCVSS 7.5No exploitEPSS 47%

    hpe · insight remote supportNov 26, 2024

  • ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document

    CriticalCVSS 9.8No exploitEPSS 10%

    reportlab · reportlabOct 16, 2019

  • Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is vulnerable to unauthenticated blind XML injecti

    CriticalCVSS 9.8No exploitEPSS 7%

    axway · securetransportJul 26, 2019

  • paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in

    CriticalCVSS 9.8No exploitEPSS 6%

    reportlab · reportlabSep 20, 2023

  • The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows remote attackers to c

    CriticalCVSS 9.8Proof of conceptEPSS 5%

    boschsecurity · nbn-498 dinion2x day\/night ip cameras firmwareFeb 18, 2020

  • NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns E

    CriticalCVSS 9.8Proof of conceptEPSS 5%

    nsa · ghidraSep 28, 2019

  • Magento Commerce XML Injection Vulnerability In The 'City' Field Could Lead To Remote Code Execution

    CriticalCVSS 9.8No exploitEPSS 3%

    adobe · adobe commerceSep 1, 2021

  • yWorks yEd Desktop before 3.20.1 allows code execution via an XSL Transformation when using an XML file in conjunction with a custom stylesh

    CriticalCVSS 9.8No exploitEPSS 2%

    yworks · yedSep 17, 2020

  • petl before 1.68, in some configurations, allows resolution of entities in an XML document.

    CriticalCVSS 9.8No exploitEPSS 2%

    petl project · petlNov 26, 2020

  • An issue was discovered in ONLYOFFICE Document Server 5.5.0.

    CriticalCVSS 9.8No exploitEPSS 2%

    onlyoffice · document serverApr 15, 2020

  • ABB Central Licensing System - XML External Entity Injection

    CriticalCVSS 9.8No exploitEPSS 2%

    abb · 800xa systemApr 28, 2020

  • The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to conduct XML injection attacks via the url parameter to plugin_google

    CriticalCVSS 9.8No exploitEPSS 2%

    mapsplugin · googlemapsSep 14, 2017

  • It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox.

    CriticalCVSS 10.0No exploitEPSS 1%

    mozilla · firefoxDec 22, 2022

  • CVE-2013-4857
    39Monitor

    D-Link DIR-865L has PHP File Inclusion in the router xml file.

    CriticalCVSS 9.8No exploitEPSS 2%

    dlink · dir-865l firmwareOct 25, 2019

  • In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0

    CriticalCVSS 9.8No exploitEPSS 1%

    forgerock · access managementAug 25, 2021

  • CVE-2019-8158
    39Monitor

    An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.

    CriticalCVSS 9.8No exploitEPSS 1%

    magento · magentoNov 5, 2019

  • fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    fonttools · fonttoolsNov 28, 2025

  • securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx file

    HighCVSS 8.8Proof of conceptEPSS 8%

    phpoffice · phpspreadsheetNov 14, 2018

  • CVE-2014-1409
    37Monitor

    MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 have an authentication bypass vulnerability due to an XML file with

    CriticalCVSS 9.1No exploitEPSS 4%

    mobileiron · virtual smartphone platformJan 8, 2020

  • Magento Commerce XML Injection Could Lead To Remote Code Execution

    CriticalCVSS 9.1No exploitEPSS 4%

    magento · magentoFeb 11, 2021

All vulnerability classes