lxml records
7 published records for vendor lxml.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-476 NULL Pointer Dereference1
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2022-2309No exploit | NULL Pointer Dereference in lxml/lxmllxml · lxml · CWE-476 | High7.5 | — | 2.4% | Jul 5, 2022 |
30Monitor | CVE-2026-41066No exploit | lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local fileslxml · lxml · CWE-611 | High7.5 | — | 0.4% | Apr 24, 2026 |
29Monitor | CVE-2021-43818No exploit | HTML Cleaner allows crafted and SVG embedded scripts to pass throughlxml · lxml · CWE-74 | High7.1 | — | 2.5% | Dec 13, 2021 |
26Monitor | CVE-2014-3146Proof of concept | Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scriptinlxml · lxml · CWE-79 | Medium6.1 | — | 6.3% | May 14, 2014 |
25Monitor | CVE-2021-28957No exploit | An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3.lxml · lxml · CWE-79 | Medium6.1 | — | 4.0% | Mar 21, 2021 |
25Monitor | CVE-2020-27783No exploit | A XSS vulnerability was discovered in python-lxml's clean module.lxml · lxml · CWE-79 | Medium6.1 | — | 4.0% | Dec 3, 2020 |
25Monitor | CVE-2018-19787No exploit | An issue was discovered in lxml before 4.2.5.lxml · lxml · CWE-79 | Medium6.1 | — | 2.4% | Dec 2, 2018 |
- CVE-2022-230931Monitor
NULL Pointer Dereference in lxml/lxml
HighCVSS 7.5No exploitEPSS 2%lxml · lxmlJul 5, 2022
- CVE-2026-4106630Monitor
lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files
HighCVSS 7.5No exploitEPSS 0%lxml · lxmlApr 24, 2026
- CVE-2021-4381829Monitor
HTML Cleaner allows crafted and SVG embedded scripts to pass through
HighCVSS 7.1No exploitEPSS 2%lxml · lxmlDec 13, 2021
- CVE-2014-314626Monitor
Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scriptin
MediumCVSS 6.1Proof of conceptEPSS 6%lxml · lxmlMay 14, 2014
- CVE-2021-2895725Monitor
An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3.
MediumCVSS 6.1No exploitEPSS 4%lxml · lxmlMar 21, 2021
- CVE-2020-2778325Monitor
A XSS vulnerability was discovered in python-lxml's clean module.
MediumCVSS 6.1No exploitEPSS 4%lxml · lxmlDec 3, 2020
- CVE-2018-1978725Monitor
An issue was discovered in lxml before 4.2.5.
MediumCVSS 6.1No exploitEPSS 2%lxml · lxmlDec 2, 2018