<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – XML Injection (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/xml-injection.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/xml-injection-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – XML Injection (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:51 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-28770 – Improper neutralization of special elements in the /IDC_Logging/checkifdone.cgi ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28770</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28770</guid>
    <pubDate>Wed, 04 Mar 2026 07:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28770</strong></p>
  <p>Improper neutralization of special elements in the /IDC_Logging/checkifdone.cgi script in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver Web management Interface version 101 allows for XML Injection. The application reflects un-sanitized user input from the `file` parameter directly into a CDATA block, allowing an authenticated attacker to break out of the tag…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28770">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24404 – XML Injection RCE by parse http sitemap xml response vulnerability in Apache Her...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24404</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24404</guid>
    <pubDate>Tue, 09 Sep 2025 10:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24404</strong></p>
  <p>XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat.             The attacker needs to have an authenticated account with access, and add monitor parsed by xml, returned special content can trigger the XML parsing vulnerability.  This issue affects Apache HertzBeat (incubating): before 1.7.0.  Users are recommended to upgrade to version 1.7.0, which fixes the is…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24404">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49538 – ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an XML ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49538</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49538</guid>
    <pubDate>Tue, 08 Jul 2025 21:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49538</strong></p>
  <p>ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an XML Injection vulnerability that could lead to arbitrary file system read. An attacker can exploit this issue by injecting crafted XML or XPath queries to access unauthorized files or lead to denial of service. Exploitation of this issue does not require user interaction, and attack must have access to shared secrets.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49538">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-7098 – Improper Restriction of XML External Entity Reference vulnerability in SFS Consu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7098</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7098</guid>
    <pubDate>Mon, 16 Sep 2024 15:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-7098</strong></p>
  <p>Improper Restriction of XML External Entity Reference vulnerability in SFS Consulting ww.Winsure allows XML Injection.  This issue affects ww.Winsure: before 4.6.2.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7098">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-34740 – In attributeBytesBase64 and attributeBytesHex of BinaryXmlSerializer.java, there...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34740</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34740</guid>
    <pubDate>Thu, 15 Aug 2024 22:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-34740</strong></p>
  <p>In attributeBytesBase64 and attributeBytesHex of BinaryXmlSerializer.java, there is a possible arbitrary XML injection due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34740">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-27328 – Parallels Desktop Toolgate XML Injection Local Privilege Escalation Vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-27328</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-27328</guid>
    <pubDate>Fri, 03 May 2024 02:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-27328</strong></p>
  <p>Parallels Desktop Toolgate XML Injection Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability.  The specific flaw exists within the Toolgate component. The is…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-27328">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36023 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36023</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36023</guid>
    <pubDate>Wed, 06 Sep 2023 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36023</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36023">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-46751 – Improper Restriction of XML External Entity Reference, XML Injection (aka Blind ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-46751</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-46751</guid>
    <pubDate>Mon, 21 Aug 2023 07:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-46751</strong></p>
  <p>Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache Ivy.This issue affects any version of Apache Ivy prior to 2.5.2.  When Apache Ivy prior to 2.5.2 parses XML files - either its own configuration, Ivy files or Apache Maven POMs - it will allow downloading external document type definitions and expand…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-46751">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38207 – Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38207</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38207</guid>
    <pubDate>Wed, 09 Aug 2023 08:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38207</strong></p>
  <p>Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) are affected by a XML Injection (aka Blind XPath Injection) vulnerability that could lead in minor arbitrary file system read. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38207">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22247 – Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are af...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22247</guid>
    <pubDate>Mon, 27 Mar 2023 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22247</strong></p>
  <p>Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an XML Injection vulnerability that could lead to arbitrary file system read. An unauthenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-35259 – XML Injection with Endpoint Manager 2022. 3 and below causing a download of a ma...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-35259</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-35259</guid>
    <pubDate>Mon, 05 Dec 2022 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-35259</strong></p>
  <p>XML Injection with Endpoint Manager 2022. 3 and below causing a download of a malicious file to run and possibly execute to gain unauthorized privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-35259">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-34253 – Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-34253</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-34253</guid>
    <pubDate>Tue, 16 Aug 2022 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-34253</strong></p>
  <p>Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an XML Injection vulnerability in the Widgets Module. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34253">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32458 – Digiwin BPM has a XML External Entity Injection (XXE) vulnerability due to insuf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32458</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32458</guid>
    <pubDate>Wed, 20 Jul 2022 02:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32458</strong></p>
  <p>Digiwin BPM has a XML External Entity Injection (XXE) vulnerability due to insufficient validation for user input. An unauthenticated remote attacker can perform XML injection attack to access arbitrary system files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32458">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36033 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36033</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36033</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36033</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Module. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36033">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36028 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36028</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36028</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36028</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability when saving a configurable product. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36028">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36022 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36022</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36022</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36022</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36022">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36020 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36020</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36020</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36020</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the 'City' field. An unauthenticated attacker can trigger a specially crafted script to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36020">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-37154 – In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37154</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37154</guid>
    <pubDate>Wed, 25 Aug 2021 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-37154</strong></p>
  <p>In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37154">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-21025 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21025</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21025</guid>
    <pubDate>Thu, 11 Feb 2021 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-21025</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to XML injection in the product layout updates. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21025">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-21019 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21019</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21019</guid>
    <pubDate>Thu, 11 Feb 2021 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-21019</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to XML injection in the Widgets module. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21019">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-11535 – An issue was discovered in ONLYOFFICE Document Server 5.5.0. An attacker can cra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11535</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11535</guid>
    <pubDate>Wed, 15 Apr 2020 15:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-11535</strong></p>
  <p>An issue was discovered in ONLYOFFICE Document Server 5.5.0. An attacker can craft a malicious .docx file, and exploit XML injection to enter an attacker-controlled parameter into the x2t binary, to rewrite this binary and/or libxcb.so.1, and execute code on a victim's server.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11535">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2015-6970 – The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Camera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-6970</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-6970</guid>
    <pubDate>Tue, 18 Feb 2020 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2015-6970</strong></p>
  <p>The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows remote attackers to conduct XML injection attacks via the idstring parameter to rcp.xml.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-6970">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-16174 – An XML injection vulnerability was found in Limesurvey before 3.17.14 that allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16174</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16174</guid>
    <pubDate>Mon, 09 Sep 2019 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-16174</strong></p>
  <p>An XML injection vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to import specially crafted XML files and execute code or compromise data integrity.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16174">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-14277 – Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API confi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14277</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14277</guid>
    <pubDate>Fri, 26 Jul 2019 04:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-14277</strong></p>
  <p>Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is vulnerable to unauthenticated blind XML injection (and XXE) in the resetPassword functionality via the REST API. This vulnerability can lead to local file disclosure, DoS, or URI invocation attacks (i.e., SSRF with resultant remote code execution). NOTE: The vendor disputes this issues as not being a vuln…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14277">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-1010017 – libnmap &lt; v0.6.3 is affected by: XML Injection. The impact is: Denial of service...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-1010017</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-1010017</guid>
    <pubDate>Mon, 15 Jul 2019 03:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-1010017</strong></p>
  <p>libnmap < v0.6.3 is affected by: XML Injection. The impact is: Denial of service (DoS) by consuming resources. The component is: XML Parsing. The attack vector is: Specially crafted XML payload.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-1010017">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-12787 – An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BET...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12787</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12787</guid>
    <pubDate>Mon, 10 Jun 2019 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-12787</strong></p>
  <p>An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA. There is a command injection in HNAP1 SetWanSettings via an XML injection of the value of the Gateway key.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12787">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-12786 – An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BET...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12786</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12786</guid>
    <pubDate>Mon, 10 Jun 2019 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-12786</strong></p>
  <p>An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA. There is a command injection in HNAP1 SetWanSettings via an XML injection of the value of the IPAddress key.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12786">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-9362 – ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Confi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-9362</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-9362</guid>
    <pubDate>Mon, 25 Mar 2019 16:29:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-9362</strong></p>
  <p>ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-9362">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-16784 – DedeCMS 5.7 SP2 allows XML injection, and resultant remote code execution, via a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-16784</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-16784</guid>
    <pubDate>Fri, 21 Sep 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-16784</strong></p>
  <p>DedeCMS 5.7 SP2 allows XML injection, and resultant remote code execution, via a "<file type='file' name='../" substring.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-16784">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-16785 – XML injection vulnerability exists in the file of DedeCMS V5.7 SP2 version, whic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-16785</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-16785</guid>
    <pubDate>Wed, 19 Sep 2018 15:29:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-16785</strong></p>
  <p>XML injection vulnerability exists in the file of DedeCMS V5.7 SP2 version, which can be utilized by attackers to create script file to obtain webshell</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-16785">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1000632 – dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1000632</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1000632</guid>
    <pubDate>Mon, 20 Aug 2018 19:31:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1000632</strong></p>
  <p>dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000632">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1000526 – Openpsa contains a XML Injection vulnerability in RSS file upload feature that c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1000526</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1000526</guid>
    <pubDate>Tue, 26 Jun 2018 16:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1000526</strong></p>
  <p>Openpsa contains a XML Injection vulnerability in RSS file upload feature that can result in Remote denial of service. This attack appear to be exploitable via Specially crafted XML file. This vulnerability appears to have been fixed in after commit 4974a26.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000526">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1000090 – textpattern version version 4.6.2 contains a XML Injection vulnerability in Impo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1000090</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1000090</guid>
    <pubDate>Tue, 13 Mar 2018 15:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1000090</strong></p>
  <p>textpattern version version 4.6.2 contains a XML Injection vulnerability in Import XML feature that can result in Denial of service in context to the web server by exhausting server memory resources. This attack appear to be exploitable via Uploading a specially crafted XML file.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000090">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-7429 – The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to conduct ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-7429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-7429</guid>
    <pubDate>Thu, 14 Sep 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-7429</strong></p>
  <p>The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to conduct XML injection attacks via the url parameter to plugin_googlemap2_proxy.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-7429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-10603 – An XML injection vulnerability in Junos OS CLI can allow a locally authenticated...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-10603</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-10603</guid>
    <pubDate>Mon, 17 Jul 2017 13:18:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-10603</strong></p>
  <p>An XML injection vulnerability in Junos OS CLI can allow a locally authenticated user to elevate privileges and run arbitrary commands as the root user. This issue was found during internal product security testing. Affected releases are Juniper Networks Junos OS 15.1X53 prior to 15.1X53-D47, 15.1 prior to 15.1R3. Junos versions prior to 15.1 are not affected. No other Juniper Networks products o…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-10603">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-6662 – A vulnerability in the web-based user interface of Cisco Prime Infrastructure (P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-6662</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-6662</guid>
    <pubDate>Mon, 26 Jun 2017 07:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-6662</strong></p>
  <p>A vulnerability in the web-based user interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker read and write access to information stored in the affected system as well as perform remote code execution. The attacker must have valid user credentials. The vulnerability is due to improper handling of XML External Enti…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-6662">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-2161 – XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizz...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2161</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2161</guid>
    <pubDate>Tue, 20 Aug 2013 22:55:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-2161</strong></p>
  <p>XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift responses via an account name.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2161">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-2079 – MediaCAST 8 and earlier allows remote attackers to have an unspecified impact vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-2079</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-2079</guid>
    <pubDate>Tue, 10 May 2011 19:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-2079</strong></p>
  <p>MediaCAST 8 and earlier allows remote attackers to have an unspecified impact via a (1) CP_RIGHTSOURCE or (2) bdclient_Inventive cookie to the default URI under inventivex/managetraining/, related to an "XML injection" issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-2079">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-5024 – Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-5024</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-5024</guid>
    <pubDate>Thu, 13 Nov 2008 11:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-5024</strong></p>
  <p>Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection attacks via the default namespace in an E4X document.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-5024">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
