VYPR

CWE-917

Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')

BaseIncomplete

Description

The product constructs all or part of an expression language (EL) statement in a framework such as a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.

Frameworks such as Java Server Page (JSP) allow a developer to insert executable expressions within otherwise-static content. When the developer is not aware of the executable nature of these expressions and/or does not disable them, then if an attacker can inject expressions, this could lead to code execution or other unexpected behaviors.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (211)

page 10 of 11
  • CVE-2022-4146HigJul 18, 2023
    risk 0.47cvss 7.3epss 0.01

    Expression Language Injection vulnerability in Hitachi Replication Manager on Windows, Linux, Solaris allows Code Injection.This issue affects Hitachi Replication Manager: before 8.8.5-02.

  • CVE-2018-16621HigNov 15, 2018
    risk 0.47cvss 7.2epss 0.02

    Sonatype Nexus Repository Manager before 3.14 allows Java Expression Language Injection.

  • CVE-2026-41729HigJun 10, 2026
    risk 0.46cvss 8.1epss 0.00

    Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests. When a persistent entity exposes a Map-typed property, the JSON Pointer path segment used as the map key is embedded…

  • CVE-2026-41883HigMay 8, 2026
    risk 0.46cvss 8.1epss 0.00

    OmniFaces is a utility library for Faces. Prior to versions 1.14.2, 2.7.32, 3.14.16, 4.7.5, and 5.2.3, there is a server-side EL injection leading to Remote Code Execution (RCE). This affects applications that use CDNResourceHandler with a wildcard CDN mapping (e.g.…

  • CVE-2026-33938HigMar 27, 2026
    risk 0.46cvss 8.1epss 0.01

    Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the `@partial-block` special variable is stored in the template data context and is reachable and mutable from within a template via helpers that accept arbitrary…

  • CVE-2026-24737HigFeb 2, 2026
    risk 0.46cvss 8.1epss 0.01

    jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass unsanitized input to one of the following…

  • CVE-2026-28201HigMay 7, 2026
    risk 0.44cvss 7.8epss 0.00

    An improper input validation, together with an overly permissive default CORS configuration in Open Notebook v1.8.1 allows remote attacker to trick a legitimate user to alter or delete arbitrary database entries via specially crafted malicious URL. Depending on the deployment,…

  • CVE-2026-32695HigMar 27, 2026
    risk 0.43cvss 7.7epss 0.00

    Traefik is an HTTP reverse proxy and load balancer. Prior to versions 3.6.11 and 3.7.0-ea.2, Traefik's Knative provider builds router rules by interpolating user-controlled values into backtick-delimited rule expressions without escaping. In live cluster validation, Knative…

  • CVE-2020-15143HigAug 20, 2020
    risk 0.43cvss 7.7epss 0.02

    In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, rrequest parameters injected inside an expression evaluated by `symfony/expression-language` package haven't been sanitized properly. This allows the attacker to access any public service by manipulating…

  • CVE-2026-40985MedJun 11, 2026
    risk 0.42cvss 6.4epss 0.00

    Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.

  • CVE-2026-41719MedJun 10, 2026
    risk 0.42cvss 6.4epss 0.00

    A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is passed as Sort into a repository query method that delegates evaluation to the SpelPropertyComparator. Affected versions: Spring Data KeyValue / Spring Data Redis 4.0.0 through 4.0.5;…

  • CVE-2026-44209HigMay 26, 2026
    risk 0.42cvss 7.5epss 0.01

    Banks generates meaningful LLM prompts using a template language that makes sense. Prior to 2.4.2, banks uses jinja2.Environment() (unsandboxed) to render prompt templates. Applications that pass user-supplied strings as the template argument to Prompt() are vulnerable to…

  • CVE-2026-31380MedMay 19, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

  • CVE-2022-34466MedJul 12, 2022
    risk 0.42cvss 6.5epss 0.01

    A vulnerability has been identified in Mendix Applications using Mendix 9 (All versions >= V9.11 < V9.15), Mendix Applications using Mendix 9 (V9.12) (All versions < V9.12.3). An expression injection vulnerability was discovered in the Workflow subsystem of Mendix Runtime, that…

  • CVE-2011-4343HigAug 8, 2017
    risk 0.42cvss 7.5epss 0.05

    Information disclosure vulnerability in Apache MyFaces Core 2.0.1 through 2.0.10 and 2.1.0 through 2.1.4 allows remote attackers to inject EL expressions via crafted parameters.

  • CVE-2024-7552MedAug 6, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in DataGear up to 5.0.0. It has been declared as critical. Affected by this vulnerability is the function evaluateVariableExpression of the file ConversionSqlParamValueMapper.java of the component Data Schema Page. The manipulation leads to improper…

  • CVE-2022-24847HigApr 13, 2022
    risk 0.40cvss 7.2epss 0.01

    GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The GeoServer security mechanism can perform an unchecked JNDI lookup, which in turn can be used to perform class deserialization and result in arbitrary code…

  • CVE-2025-56769MedSep 25, 2025
    risk 0.35cvss 6.5epss 0.00

    An issue was discovered in chinabugotech hutool before 5.8.4 allowing attackers to execute arbitrary expressions that lead to arbitrary method invocation and potentially remote code execution (RCE) via the QLExpressEngine class.

  • CVE-2024-9672MedDec 10, 2024
    risk 0.35cvss 5.4epss 0.00

    A reflected cross-site scripting (XSS) vulnerability exists in PaperCut NG/MF. This issue can be used to execute specially created JavaScript payloads in the browser. A user must click on a malicious link for this issue to occur.

  • CVE-2023-22665MedApr 25, 2023
    risk 0.35cvss 5.4epss 0.01

    There is insufficient checking of user queries in Apache Jena versions 4.7.0 and earlier, when invoking custom scripts. It allows a remote user to execute arbitrary javascript via a SPARQL query.