← Back
CWE-652

2 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Data within XQuery Expressions ('XQuery Injection')

The product uses external input to dynamically construct an XQuery expression used to retrieve data from an XML database, but it does not neutralize or incorrectly neutralizes that input. This allows an attacker to control the structure of the query.

JSON object

Loading...

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Convert To Pipeline
Jun 17, 2026
Apr 2, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins Convert To Pipeline Plugin 1.0 and earlier allows attackers to create a Pipeline based on a Freestyle project, potentially leading to remote code execution (RC...Show more
A cross-site request forgery (CSRF) vulnerability in Jenkins Convert To Pipeline Plugin 1.0 and earlier allows attackers to create a Pipeline based on a Freestyle project, potentially leading to remote code execution (RCE).Show less
1Clockwork Web Project
1Clockwork Web
Jun 17, 2026
Feb 2, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Clockwork Web before 0.1.2, when Rails before 5.2 is used, allows CSRF.