← Back
CWE-91

129 CVEs • Abstraction: Base

XML Injection (aka Blind XPath Injection)

The product does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system.

JSON object

Loading...

CVEs (129)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Magento
1Magento
Jun 17, 2026
Nov 6, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An attacker can craft a GET request to page cache block rendering module that gets passed to XML data...Show more
An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An attacker can craft a GET request to page cache block rendering module that gets passed to XML data processing engine without validation. The crafted key/value GET request data allows an attacker to limited access to underlying XML data.Show less
1Clipsoft
1Rexpert
Jun 17, 2026
Oct 30, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation and execution via report print function of rexpert viewer with modified XML document. User interaction is required to exploit this vulnerabili...Show more
ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation and execution via report print function of rexpert viewer with modified XML document. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page.Show less
1Dlink
1Dir 865l Firmware
Nov 21, 2024
Oct 25, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
D-Link DIR-865L has PHP File Inclusion in the router xml file.
1Reportlab
1Reportlab
Jun 17, 2026
Oct 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document with '<span color="' followed by arbitrary Python code.
1Sap
1Financial Consolidation
Jun 17, 2026
Oct 8, 2019
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
Due to missing input validation, SAP Financial Consolidation, before versions 10.0 and 10.1, enables an attacker to use crafted input to interfere with the structure of the surrounding query leading to XPath Injection.
1Ibm
1Security Directory Server
Jun 17, 2026
Oct 2, 2019
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
IBM Security Directory Server 6.4.0 does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system. IB...Show more
IBM Security Directory Server 6.4.0 does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system. IBM X-Force ID: 165812.Show less
1Nsa
1Ghidra
Jun 17, 2026
Sep 28, 2019
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns Explorer is used with a modified XML document. This occurs in Features/BytePatter...Show more
NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns Explorer is used with a modified XML document. This occurs in Features/BytePatterns/src/main/java/ghidra/bitpatterns/info/FileBitPatternInfoReader.java. An attack could start with an XML document that was originally created by DumpFunctionPatternInfoScript but then directly modified by an attacker (for example, to make a java.lang.Runtime.exec call).Show less
1Axway
1Securetransport
Jun 17, 2026
Jul 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is vulnerable to unauthenticated blind XML injection (and XXE) in the resetPassword functionality via the REST API. This vulnerabi...Show more
Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is vulnerable to unauthenticated blind XML injection (and XXE) in the resetPassword functionality via the REST API. This vulnerability can lead to local file disclosure, DoS, or URI invocation attacks (i.e., SSRF with resultant remote code execution). NOTE: The vendor disputes this issues as not being a vulnerability because “All attacks that use external entities are blocked (no external DTD or file inclusions, no SSRF). The impact on confidentiality, integrity and availability is not proved on any version.Show less
1Libnmap
1Libnmap
Jun 17, 2026
Jul 15, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
libnmap < v0.6.3 is affected by: XML Injection. The impact is: Denial of service (DoS) by consuming resources. The component is: XML Parsing. The attack vector is: Specially crafted XML payload.
2Debian
Otrs
2Debian Linux
Otrs
Jun 17, 2026
May 22, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in Open Ticket Request System (OTRS) 5.x through 5.0.34, 6.x through 6.0.17, and 7.x through 7.0.6. An attacker who is logged into OTRS as an agent user with appropriate permissions may try to imp...Show more
An issue was discovered in Open Ticket Request System (OTRS) 5.x through 5.0.34, 6.x through 6.0.17, and 7.x through 7.0.6. An attacker who is logged into OTRS as an agent user with appropriate permissions may try to import carefully crafted Report Statistics XML that will result in reading of arbitrary files on the OTRS filesystem.Show less
1Sap
1Businessobjects Business Intelligence
Jun 17, 2026
Mar 12, 2019
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
SAP BusinessObjects Business Intelligence Platform (CMC Module), versions 4.10, 4.20 and 4.30, does not sufficiently validate an XML document accepted from an untrusted source.
1Phpoffice
1Phpspreadsheet
Nov 21, 2024
Nov 14, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx file
1Sap
1Netweaver
Nov 21, 2024
Nov 13, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Knowledge Management (XMLForms) in SAP NetWeaver, versions 7.30, 7.31, 7.40 and 7.50 does not sufficiently validate an XML document accepted from an untrusted source.
1Dedecms
1Dedecms
Nov 21, 2024
Sep 21, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
DedeCMS 5.7 SP2 allows XML injection, and resultant remote code execution, via a "<file type='file' name='../" substring.
1Dedecms
1Dedecms
Nov 21, 2024
Sep 19, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
XML injection vulnerability exists in the file of DedeCMS V5.7 SP2 version, which can be utilized by attackers to create script file to obtain webshell
5Debian
Dom4j ProjectNetapp+2 more
14Debian Linux
Dom4jFlexcube Investor Servicing+11 more
Nov 21, 2024
Aug 20, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection....Show more
dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.Show less
1Openpsa2
1Openpsa
Nov 21, 2024
Jun 26, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Openpsa contains a XML Injection vulnerability in RSS file upload feature that can result in Remote denial of service. This attack appear to be exploitable via Specially crafted XML file. This vulnerability appears to ha...Show more
Openpsa contains a XML Injection vulnerability in RSS file upload feature that can result in Remote denial of service. This attack appear to be exploitable via Specially crafted XML file. This vulnerability appears to have been fixed in after commit 4974a26.Show less
1Epic
1Mychart
Nov 21, 2024
Feb 20, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
XPath injection vulnerability in Epic MyChart allows remote attackers to access contents of an XML document containing static display strings, such as field labels, via the topic parameter to help.asp. NOTE: this was ori...Show more
XPath injection vulnerability in Epic MyChart allows remote attackers to access contents of an XML document containing static display strings, such as field labels, via the topic parameter to help.asp. NOTE: this was originally reported as a SQL injection vulnerability, but this may be inaccurate.Show less
1Samlify Project
1Samlify
Nov 21, 2024
Jan 2, 2018
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
An XML Signature Wrapping vulnerability exists in Samlify 2.2.0 and earlier, and in predecessor Express-saml2 which could allow attackers to impersonate arbitrary users.
1Mapsplugin
1Googlemaps
May 13, 2026
Sep 14, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to conduct XML injection attacks via the url parameter to plugin_googlemap2_proxy.php.