VYPR

CWE-91

XML Injection (aka Blind XPath Injection)

BaseDraft

Description

The product does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system.

Within XML, special elements could include reserved words or characters such as "<", ">", """, and "&", which could then be used to add new data or modify XML syntax.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-250 · CAPEC-83

CVEs mapped to this weakness (138)

page 3 of 7
  • CVE-2026-11169HigJun 4, 2026
    risk 0.53cvss 8.1epss 0.00

    Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted XML file. (Chromium security severity: Medium)

  • CVE-2025-25589HigMar 18, 2025
    risk 0.53cvss 8.1epss 0.00

    An XML external entity (XXE) injection vulnerability in the component /weixin/aes/XMLParse.java of yimioa before v2024.07.04 allows attackers to execute arbitrary code via supplying a crafted XML file.

  • CVE-2024-47113HigJan 18, 2025
    risk 0.53cvss 8.1epss 0.01

    IBM ICP - Voice Gateway 1.0.2, 1.0.2.4, 1.0.3, 1.0.4, 1.0.5, 1.0.6. 1.0.7, 1.0.7.1, and 1.0.8 could allow remote attacker to send specially crafted XML statements, which would allow them to attacker to view or modify information in the XML document.

  • CVE-2024-42374HigAug 13, 2024
    risk 0.53cvss 8.2epss 0.01

    BEx Web Java Runtime Export Web Service does not sufficiently validate an XML document accepted from an untrusted source. An attacker can retrieve information from the SAP ADS system and exhaust the number of XMLForm service which makes the SAP ADS rendering (PDF creation)…

  • CVE-2022-2458HigAug 10, 2022
    risk 0.53cvss 8.2epss 0.01

    XML external entity injection(XXE) is a vulnerability that allows an attacker to interfere with an application's processing of XML data. This attack occurs when XML input containing a reference to an external entity is processed by a weakly configured XML parser. The software…

  • CVE-2022-22784HigMay 18, 2022
    risk 0.53cvss 8.1epss 0.04

    The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly parse XML stanzas in XMPP messages. This can allow a malicious user to break out of the current XMPP message context and create a new message context to have the…

  • CVE-2020-6271HigJun 10, 2020
    risk 0.53cvss 8.2epss 0.01

    SAP Solution Manager (Problem Context Manager), version 7.2, does not perform the necessary authentication, allowing an attacker to consume large amounts of memory, causing the system to crash and read restricted data (files visible for technical administration users of the…

  • CVE-2019-0268HigMar 12, 2019
    risk 0.53cvss 8.1epss 0.02

    SAP BusinessObjects Business Intelligence Platform (CMC Module), versions 4.10, 4.20 and 4.30, does not sufficiently validate an XML document accepted from an untrusted source.

  • CVE-2016-6272HigFeb 20, 2018
    risk 0.53cvss 7.5epss 0.21

    XPath injection vulnerability in Epic MyChart allows remote attackers to access contents of an XML document containing static display strings, such as field labels, via the topic parameter to help.asp. NOTE: this was originally reported as a SQL injection vulnerability, but this…

  • CVE-2024-53674HigNov 26, 2024
    risk 0.51cvss 7.3epss 0.47

    An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

  • CVE-2024-34740HigAug 15, 2024
    risk 0.51cvss 7.8epss 0.00

    In attributeBytesBase64 and attributeBytesHex of BinaryXmlSerializer.java, there is a possible arbitrary XML injection due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-27328HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Parallels Desktop Toolgate XML Injection Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the…

  • CVE-2022-35259HigDec 5, 2022
    risk 0.51cvss 7.8epss 0.01

    XML Injection with Endpoint Manager 2022. 3 and below causing a download of a malicious file to run and possibly execute to gain unauthorized privileges.

  • CVE-2020-29599HigDec 7, 2020
    risk 0.51cvss 7.8epss 0.08

    ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authenticate option, which allows setting a password for password-protected PDF files. The user-controlled password was not properly escaped/sanitized and it was therefore possible to inject additional shell…

  • CVE-2015-3932HigJul 21, 2017
    risk 0.51cvss 7.8epss 0.02

    Netlock Mokka before 2.7.8.1204 allows remote attackers to perform XML signature wrapping attacks via an e-akta signed document with a ds:Object node with a crafted payload prepended to a valid ds:Object.

  • CVE-2015-3931HigJul 21, 2017
    risk 0.51cvss 7.8epss 0.02

    Microsec e-Szigno before 3.2.7.12 allows remote attackers to perform XML signature wrapping attacks via an e-akta signed document with a ds:Object node with a crafted payload prepended to a valid ds:Object.

  • CVE-2026-46490HigJun 8, 2026
    risk 0.50cvss 8.8epss 0.00

    samlify is a Node.js library for SAML single sign-on. Prior to version 2.13.0, samlify’s template substitution only escapes attribute contexts. Values inserted into element text (e.g., <saml:AttributeValue>) are not escaped. A normal user can inject XML markup into an…

  • CVE-2026-40165HigMay 21, 2026
    risk 0.50cvss 8.7epss 0.01

    authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2 were vulnerable to Authentication Bypass through SAML NameID XML Comment Injection. Due to how authentik extracted the NameID value from a SAML assertion, it…

  • CVE-2025-59952HigSep 30, 2025
    risk 0.50cvss epss 0.00

    MinIO Java SDK is a Simple Storage Service (aka S3) client to perform bucket and object operations to any Amazon S3 compatible object storage service. In minio-java versions prior to 8.6.0, XML tag values containing references to system properties or environment variables were…

  • CVE-2025-24404HigSep 9, 2025
    risk 0.50cvss 8.8epss 0.01

    XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat. The attacker needs to have an authenticated account with access, and add monitor parsed by xml, returned special content can trigger the XML parsing vulnerability. This issue…