VYPR

CWE-643

Improper Neutralization of Data within XPath Expressions ('XPath Injection')

BaseIncompleteLikelihood: High

Description

The product uses external input to dynamically construct an XPath expression used to retrieve data from an XML database, but it does not neutralize or incorrectly neutralizes that input. This allows an attacker to control the structure of the query.

The net effect is that the attacker will have control over the information selected from the XML database and may use that ability to control application flow, modify logic, retrieve unauthorized data, or bypass important checks (e.g. authentication).

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (15)

  • CVE-2026-44962CriMay 29, 2026
    risk 0.64cvss 9.9epss 0.01

    Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged user to execute arbitrary operating system…

  • CVE-2026-24343HigFeb 10, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat: from 1.7.1 before 1.8.0. Users are recommended to upgrade to version 1.8.0, which fixes the issue.

  • CVE-2024-39565HigJul 10, 2024
    risk 0.57cvss 8.8epss 0.01

    An Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in J-Web shipped with Juniper Networks Junos OS allows an unauthenticated, network-based attacker to execute remote commands on the target device.  While an administrator is logged…

  • CVE-2026-9390CriAug 3, 2026
    risk 0.52cvss 9.1epss 0.00

    XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_signed_xml() in lib/XML/Sig.pm build XPath expressions by concatenating the SignedInfo/Reference/@URI value read from the document being verified. The value is neither escaped nor…

  • CVE-2024-8955HigMar 20, 2025
    risk 0.49cvss 7.5epss 0.01

    A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.4. This vulnerability allows an attacker to read the contents of any file in the system by exploiting the BROWSERTOOL_GOTO_PAGE and BROWSERTOOL_GET_PAGE_DETAILS actions.

  • CVE-2020-25162HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    A XPath injection vulnerability in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows unauthenticated remote attackers to access sensitive information and escalate privileges.

  • CVE-2026-40699MedMay 13, 2026
    risk 0.42cvss 6.5epss 0.00

    A vulnerability exists in the undisclosed pages in the Configuration utility that may allow a low-privileged authenticated attacker to access to undisclosed sensitive information.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2023-36433MedOct 10, 2023
    risk 0.42cvss 6.5epss 0.02

    Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

  • CVE-2023-36429MedOct 10, 2023
    risk 0.42cvss 6.5epss 0.02

    Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

  • CVE-2023-24922MedMar 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

  • CVE-2025-20218MedAug 14, 2025
    risk 0.32cvss 4.9epss 0.00

    A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to retrieve sensitive information from an affected device. This vulnerability is due to insufficient input validation.…

  • CVE-2025-11844MedOct 22, 2025
    risk 0.28cvss 5.4epss 0.00

    Hugging Face Smolagents version 1.20.0 contains an XPath injection vulnerability in the search_item_ctrl_f function located in src/smolagents/vision_web_browser.py. The function constructs an XPath query by directly concatenating user-supplied input into the XPath expression…

  • CVE-2022-43840MedApr 14, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive application data and/or determine the structure of the XML document.

  • CVE-2024-2648MedMar 19, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability, which was classified as problematic, was found in Netentsec NS-ASG Application Security Gateway 6.3. Affected is an unknown function of the file /nac/naccheck.php. The manipulation of the argument username leads to improper neutralization of data within xpath…

  • CVE-2024-2645MedMar 19, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic has been found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /vpnweb/resetpwd/resetpwd.php. The manipulation of the argument UserId leads to improper neutralization of data within xpath…