CWE-91 · 135 records
XML Injection (aka Blind XPath Injection)
CVEs in this class
135 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2020-0646Weaponized | A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote microsoft · .net framework · CWE-91 | Critical9.8 | KEV | 99.2% | Jan 14, 2020 |
62This week | CVE-2023-27253Weaponized | A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbinetgate · pfsense · CWE-91 | High8.8 | — | 89.5% | Mar 17, 2023 |
62This week | CVE-2023-46214Weaponized | Remote code execution (RCE) in Splunk Enterprise through Insecure XML Parsingsplunk · cloud · CWE-91 | High8.8 | — | 89.2% | Nov 16, 2023 |
55Plan | CVE-2024-53675No exploit | An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certainhpe · insight remote support · CWE-91 | High7.5 | — | 83.6% | Nov 26, 2024 |
53Plan | CVE-2023-43187Proof of concept | A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackersnodebb · nodebb · CWE-91 | Critical9.8 | — | 47.4% | Sep 27, 2023 |
44Plan | CVE-2024-53674No exploit | An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certainhpe · insight remote support · CWE-91 | High7.5 | — | 46.7% | Nov 26, 2024 |
42Plan | CVE-2019-17626No exploit | ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document reportlab · reportlab · CWE-91 | Critical9.8 | — | 10.2% | Oct 16, 2019 |
41Plan | CVE-2019-14277No exploit | Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is vulnerable to unauthenticated blind XML injectiaxway · securetransport · CWE-91 | Critical9.8 | — | 7.3% | Jul 26, 2019 |
41Plan | CVE-2019-19450No exploit | paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in reportlab · reportlab · CWE-91 | Critical9.8 | — | 6.0% | Sep 20, 2023 |
41Plan | CVE-2015-6970Proof of concept | The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows remote attackers to cboschsecurity · nbn-498 dinion2x day\/night ip cameras firmware · CWE-91 | Critical9.8 | — | 5.3% | Feb 18, 2020 |
41Plan | CVE-2019-16941Proof of concept | NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns Ensa · ghidra · CWE-91 | Critical9.8 | — | 5.1% | Sep 28, 2019 |
40Plan | CVE-2021-36020No exploit | Magento Commerce XML Injection Vulnerability In The 'City' Field Could Lead To Remote Code Executionadobe · adobe commerce · CWE-91 | Critical9.8 | — | 2.7% | Sep 1, 2021 |
40Plan | CVE-2020-25216No exploit | yWorks yEd Desktop before 3.20.1 allows code execution via an XSL Transformation when using an XML file in conjunction with a custom styleshyworks · yed · CWE-91 | Critical9.8 | — | 2.4% | Sep 17, 2020 |
40Plan | CVE-2020-29128No exploit | petl before 1.68, in some configurations, allows resolution of entities in an XML document.petl project · petl · CWE-91 | Critical9.8 | — | 2.3% | Nov 26, 2020 |
40Plan | CVE-2020-11535No exploit | An issue was discovered in ONLYOFFICE Document Server 5.5.0.onlyoffice · document server · CWE-91 | Critical9.8 | — | 2.3% | Apr 15, 2020 |
40Plan | CVE-2020-8479No exploit | ABB Central Licensing System - XML External Entity Injectionabb · 800xa system · CWE-91 | Critical9.8 | — | 2.3% | Apr 28, 2020 |
40Plan | CVE-2013-7429No exploit | The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to conduct XML injection attacks via the url parameter to plugin_googlemapsplugin · googlemaps · CWE-91 | Critical9.8 | — | 2.2% | Sep 14, 2017 |
40Plan | CVE-2021-4140No exploit | It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox.mozilla · firefox · CWE-91 | Critical10.0 | — | 1.3% | Dec 22, 2022 |
39Monitor | CVE-2013-4857No exploit | D-Link DIR-865L has PHP File Inclusion in the router xml file.dlink · dir-865l firmware · CWE-91 | Critical9.8 | — | 1.6% | Oct 25, 2019 |
39Monitor | CVE-2021-37154No exploit | In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 forgerock · access management · CWE-91 | Critical9.8 | — | 1.4% | Aug 25, 2021 |
39Monitor | CVE-2019-8158No exploit | An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.magento · magento · CWE-91 | Critical9.8 | — | 1.3% | Nov 5, 2019 |
39Monitor | CVE-2025-66034Proof of concept | fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLibfonttools · fonttools · CWE-91 | Critical9.8 | — | 0.5% | Nov 28, 2025 |
37Monitor | CVE-2018-19277Proof of concept | securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx filephpoffice · phpspreadsheet · CWE-91 | High8.8 | — | 7.8% | Nov 14, 2018 |
37Monitor | CVE-2014-1409No exploit | MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 have an authentication bypass vulnerability due to an XML file with mobileiron · virtual smartphone platform · CWE-91 | Critical9.1 | — | 4.0% | Jan 8, 2020 |
37Monitor | CVE-2021-21019No exploit | Magento Commerce XML Injection Could Lead To Remote Code Executionmagento · magento · CWE-91 | Critical9.1 | — | 3.6% | Feb 11, 2021 |
- CVE-2020-064699Now
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote
CriticalCVSS 9.8KEVWeaponizedEPSS 99%microsoft · .net frameworkJan 14, 2020
- CVE-2023-2725362This week
A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbi
HighCVSS 8.8WeaponizedEPSS 90%netgate · pfsenseMar 17, 2023
- CVE-2023-4621462This week
Remote code execution (RCE) in Splunk Enterprise through Insecure XML Parsing
HighCVSS 8.8WeaponizedEPSS 89%splunk · cloudNov 16, 2023
- CVE-2024-5367555Plan
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain
HighCVSS 7.5No exploitEPSS 84%hpe · insight remote supportNov 26, 2024
- CVE-2023-4318753Plan
A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers
CriticalCVSS 9.8Proof of conceptEPSS 47%nodebb · nodebbSep 27, 2023
- CVE-2024-5367444Plan
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain
HighCVSS 7.5No exploitEPSS 47%hpe · insight remote supportNov 26, 2024
- CVE-2019-1762642Plan
ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document
CriticalCVSS 9.8No exploitEPSS 10%reportlab · reportlabOct 16, 2019
- CVE-2019-1427741Plan
Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is vulnerable to unauthenticated blind XML injecti
CriticalCVSS 9.8No exploitEPSS 7%axway · securetransportJul 26, 2019
- CVE-2019-1945041Plan
paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in
CriticalCVSS 9.8No exploitEPSS 6%reportlab · reportlabSep 20, 2023
- CVE-2015-697041Plan
The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows remote attackers to c
CriticalCVSS 9.8Proof of conceptEPSS 5%boschsecurity · nbn-498 dinion2x day\/night ip cameras firmwareFeb 18, 2020
- CVE-2019-1694141Plan
NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns E
CriticalCVSS 9.8Proof of conceptEPSS 5%nsa · ghidraSep 28, 2019
- CVE-2021-3602040Plan
Magento Commerce XML Injection Vulnerability In The 'City' Field Could Lead To Remote Code Execution
CriticalCVSS 9.8No exploitEPSS 3%adobe · adobe commerceSep 1, 2021
- CVE-2020-2521640Plan
yWorks yEd Desktop before 3.20.1 allows code execution via an XSL Transformation when using an XML file in conjunction with a custom stylesh
CriticalCVSS 9.8No exploitEPSS 2%yworks · yedSep 17, 2020
- CVE-2020-2912840Plan
petl before 1.68, in some configurations, allows resolution of entities in an XML document.
CriticalCVSS 9.8No exploitEPSS 2%petl project · petlNov 26, 2020
- CVE-2020-1153540Plan
An issue was discovered in ONLYOFFICE Document Server 5.5.0.
CriticalCVSS 9.8No exploitEPSS 2%onlyoffice · document serverApr 15, 2020
- CVE-2020-847940Plan
ABB Central Licensing System - XML External Entity Injection
CriticalCVSS 9.8No exploitEPSS 2%abb · 800xa systemApr 28, 2020
- CVE-2013-742940Plan
The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to conduct XML injection attacks via the url parameter to plugin_google
CriticalCVSS 9.8No exploitEPSS 2%mapsplugin · googlemapsSep 14, 2017
- CVE-2021-414040Plan
It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox.
CriticalCVSS 10.0No exploitEPSS 1%mozilla · firefoxDec 22, 2022
- CVE-2013-485739Monitor
D-Link DIR-865L has PHP File Inclusion in the router xml file.
CriticalCVSS 9.8No exploitEPSS 2%dlink · dir-865l firmwareOct 25, 2019
- CVE-2021-3715439Monitor
In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0
CriticalCVSS 9.8No exploitEPSS 1%forgerock · access managementAug 25, 2021
- CVE-2019-815839Monitor
An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.
CriticalCVSS 9.8No exploitEPSS 1%magento · magentoNov 5, 2019
- CVE-2025-6603439Monitor
fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib
CriticalCVSS 9.8Proof of conceptEPSS 1%fonttools · fonttoolsNov 28, 2025
- CVE-2018-1927737Monitor
securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx file
HighCVSS 8.8Proof of conceptEPSS 8%phpoffice · phpspreadsheetNov 14, 2018
- CVE-2014-140937Monitor
MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 have an authentication bypass vulnerability due to an XML file with
CriticalCVSS 9.1No exploitEPSS 4%mobileiron · virtual smartphone platformJan 8, 2020
- CVE-2021-2101937Monitor
Magento Commerce XML Injection Could Lead To Remote Code Execution
CriticalCVSS 9.1No exploitEPSS 4%magento · magentoFeb 11, 2021