VYPR

CWE-917

Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')

BaseIncomplete

Description

The product constructs all or part of an expression language (EL) statement in a framework such as a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.

Frameworks such as Java Server Page (JSP) allow a developer to insert executable expressions within otherwise-static content. When the developer is not aware of the executable nature of these expressions and/or does not disable them, then if an attacker can inject expressions, this could lead to code execution or other unexpected behaviors.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (211)

page 1 of 11
  • CVE-2021-44228CriKEVDec 10, 2021
    risk 0.94cvss 10.0epss 1.00

    Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log…

  • CVE-2022-26134CriKEVJun 3, 2022
    risk 0.93cvss 9.8epss 1.00

    In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from…

  • CVE-2021-26084CriKEVAug 30, 2021
    risk 0.93cvss 9.8epss 1.00

    In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before version 6.13.23, from version…

  • CVE-2022-22963CriKEVApr 1, 2022
    risk 0.87cvss 9.8epss 1.00

    In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.

  • CVE-2021-45046CriKEVDec 14, 2021
    risk 0.87cvss 9.0epss 1.00

    It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout…

  • CVE-2022-22947CriKEVMar 3, 2022
    risk 0.81cvss 10.0epss 0.98

    In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote…

  • CVE-2020-10199HigKEVApr 1, 2020
    risk 0.80cvss 8.8epss 0.99

    Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).

  • CVE-2020-17530CriKEVDec 11, 2020
    risk 0.79cvss 9.8epss 0.96

    Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.

  • CVE-2010-1871HigKEVAug 5, 2010
    risk 0.79cvss 8.8epss 0.83

    JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to execute arbitrary code via a crafted URL. NOTE: this is only…

  • CVE-2021-31805CriApr 12, 2022
    risk 0.71cvss 9.8epss 0.85

    The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted…

  • CVE-2025-41243CriSep 16, 2025
    risk 0.65cvss 10.0epss 0.03

    Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification. An application should be considered vulnerable when all the following are true: * The application is using Spring Cloud Gateway Server Webflux (Spring Cloud Gateway Server…

  • CVE-2025-3322CriJun 6, 2025
    risk 0.65cvss epss 0.01

    An improper neutralization of inputs used in expression language allows remote code execution with the highest privileges on the server.

  • CVE-2022-22980CriJun 23, 2022
    risk 0.65cvss 9.8epss 0.17

    A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input is not sanitized.

  • CVE-2018-12533CriJun 18, 2018
    risk 0.65cvss 9.8epss 0.19

    JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via a /DATA/ substring in a path with an org.richfaces.renderkit.html.Paint2DResource$ImageData object, aka RF-14310.

  • CVE-2026-11561CriJun 11, 2026
    risk 0.64cvss 9.8epss 0.00

    Improper neutralization of special elements used in an expression language statement ('expression language injection') vulnerability in Soagen Informatics Technologies Software and Consulting Inc. Apinizer allows Code Injection. This issue affects Apinizer: from 2026.04.0…

  • CVE-2026-39842CriApr 15, 2026
    risk 0.64cvss 9.9epss 0.01

    OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulnerabilities in the rules engine that allow arbitrary code execution on the server. The JavaScript rules engine executes user-supplied scripts via Nashorn's…

  • CVE-2023-51593CriMay 3, 2024
    risk 0.64cvss 9.8epss 0.02

    Voltronic Power ViewPower Pro Expression Language Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Voltronic Power ViewPower Pro. Authentication is not required to exploit this…

  • CVE-2023-41331CriSep 12, 2023
    risk 0.64cvss 9.8epss 0.01

    SOFARPC is a Java RPC framework. Versions prior to 5.11.0 are vulnerable to remote command execution. Through a carefully crafted payload, an attacker can achieve JNDI injection or system command execution. In the default configuration of the SOFARPC framework, a blacklist is…

  • CVE-2023-27821CriMar 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Databasir v1.0.7 was discovered to contain a remote code execution (RCE) vulnerability via the mockDataScript parameter.

  • CVE-2020-7172CriOct 19, 2020
    risk 0.64cvss 9.8epss 0.07

    A templateselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).