CWE-643 · 15 records
Improper Neutralization of Data within XPath Expressions ('XPath Injection')
CVEs in this class
15 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2026-44962No exploit | Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolatwebpros · plesk · CWE-643 | Critical9.9 | — | 0.6% | May 29, 2026 |
36Monitor | CVE-2026-9390No exploit | XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookupxml\ · \ · CWE-643 | Critical9.1 | — | 0.5% | Aug 3, 2026 |
35Monitor | CVE-2026-24343No exploit | Apache HertzBeat: Uncontrolled Resource Consumption via Crafted XPath Expressionsapache · hertzbeat · CWE-643 | High8.8 | — | 0.7% | Feb 10, 2026 |
31Monitor | CVE-2020-25162No exploit | B. Braun SpaceCom, Battery Pack SP with Wi-Fi, and Data module compactplusbbraun · datamodule compactplus · CWE-643 | High7.5 | — | 1.9% | Apr 14, 2022 |
30Monitor | CVE-2024-39565No exploit | Junos OS: J-Web: An unauthenticated, network-based attacker can perform XPATH injection attack against a device.juniper · j-web · CWE-643 | High7.7 | — | 0.5% | Jul 10, 2024 |
28Monitor | CVE-2026-40699No exploit | BIG-IP Configuration utility vulnerabilityf5 · big-ip access policy manager · CWE-643 | High7.1 | — | 0.4% | May 13, 2026 |
27Monitor | CVE-2023-36429No exploit | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerabilitymicrosoft · dynamics 365 · CWE-643 | Medium6.5 | — | 2.0% | Oct 10, 2023 |
27Monitor | CVE-2023-36433No exploit | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerabilitymicrosoft · dynamics 365 · CWE-643 | Medium6.5 | — | 1.9% | Oct 10, 2023 |
26Monitor | CVE-2023-24922No exploit | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerabilitymicrosoft · dynamics 365 · CWE-643 | Medium6.5 | — | 1.5% | Mar 14, 2023 |
26Monitor | CVE-2026-11864No exploit | Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2026.ibm · cloud pak for business automation · CWE-643 | Medium6.5 | — | 0.2% | Sep 15, 2026 |
21Monitor | CVE-2024-2648No exploit | Netentsec NS-ASG Application Security Gateway naccheck.php xpath injectionnetentsec · application security gateway · CWE-643 | Medium5.3 | — | 0.7% | Mar 19, 2024 |
21Monitor | CVE-2024-2645No exploit | Netentsec NS-ASG Application Security Gateway resetpwd.php xpath injectionnetentsec · application security gateway · CWE-643 | Medium5.3 | — | 0.7% | Mar 19, 2024 |
21Monitor | CVE-2025-11844Proof of concept | XPath Injection in Hugging Face Smolagents search_item_ctrl_f Functionhuggingface · smolagents · CWE-643 | Medium5.4 | — | 0.3% | Oct 22, 2025 |
19Monitor | CVE-2025-20218No exploit | Cisco Secure Firepower Management Center Software XPATH Injection Vulnerabilitycisco · secure firewall management center · CWE-643 | Medium4.9 | — | 0.5% | Aug 14, 2025 |
17Monitor | CVE-2022-43840No exploit | IBM Aspera Console XPath injectionibm · aspera console · CWE-643 | Medium4.3 | — | 0.3% | Apr 14, 2025 |
- CVE-2026-4496239Monitor
Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolat
CriticalCVSS 9.9No exploitEPSS 1%webpros · pleskMay 29, 2026
- CVE-2026-939036Monitor
XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup
CriticalCVSS 9.1No exploitEPSS 1%xml\ · \Aug 3, 2026
- CVE-2026-2434335Monitor
Apache HertzBeat: Uncontrolled Resource Consumption via Crafted XPath Expressions
HighCVSS 8.8No exploitEPSS 1%apache · hertzbeatFeb 10, 2026
- CVE-2020-2516231Monitor
B. Braun SpaceCom, Battery Pack SP with Wi-Fi, and Data module compactplus
HighCVSS 7.5No exploitEPSS 2%bbraun · datamodule compactplusApr 14, 2022
- CVE-2024-3956530Monitor
Junos OS: J-Web: An unauthenticated, network-based attacker can perform XPATH injection attack against a device.
HighCVSS 7.7No exploitEPSS 1%juniper · j-webJul 10, 2024
- CVE-2026-4069928Monitor
BIG-IP Configuration utility vulnerability
HighCVSS 7.1No exploitEPSS 0%f5 · big-ip access policy managerMay 13, 2026
- CVE-2023-3642927Monitor
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
MediumCVSS 6.5No exploitEPSS 2%microsoft · dynamics 365Oct 10, 2023
- CVE-2023-3643327Monitor
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
MediumCVSS 6.5No exploitEPSS 2%microsoft · dynamics 365Oct 10, 2023
- CVE-2023-2492226Monitor
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
MediumCVSS 6.5No exploitEPSS 1%microsoft · dynamics 365Mar 14, 2023
- CVE-2026-1186426Monitor
Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2026.
MediumCVSS 6.5No exploitEPSS 0%ibm · cloud pak for business automationSep 15, 2026
- CVE-2024-264821Monitor
Netentsec NS-ASG Application Security Gateway naccheck.php xpath injection
MediumCVSS 5.3No exploitEPSS 1%netentsec · application security gatewayMar 19, 2024
- CVE-2024-264521Monitor
Netentsec NS-ASG Application Security Gateway resetpwd.php xpath injection
MediumCVSS 5.3No exploitEPSS 1%netentsec · application security gatewayMar 19, 2024
- CVE-2025-1184421Monitor
XPath Injection in Hugging Face Smolagents search_item_ctrl_f Function
MediumCVSS 5.4Proof of conceptEPSS 0%huggingface · smolagentsOct 22, 2025
- CVE-2025-2021819Monitor
Cisco Secure Firepower Management Center Software XPATH Injection Vulnerability
MediumCVSS 4.9No exploitEPSS 0%cisco · secure firewall management centerAug 14, 2025
- CVE-2022-4384017Monitor
IBM Aspera Console XPath injection
MediumCVSS 4.3No exploitEPSS 0%ibm · aspera consoleApr 14, 2025