<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – XML Injection</title>
  <link>https://cvedaily.com/pages/tags/xml-injection.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/xml-injection.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – XML Injection</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:51 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-41650 – fast-xml-parser allows users to process XML from JS object without C/C++ based l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41650</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41650</guid>
    <pubDate>Thu, 07 May 2026 15:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41650</strong></p>
  <p>fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Prior to version 5.7.0, XMLBuilder does not escape the "-->" sequence in comment content or the "]]>" sequence in CDATA sections when building XML from JavaScript objects. This allows XML injection when user-controlled data flows into comments or CDATA elements, leading to XSS, SOAP injection, o…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41650">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28770 – Improper neutralization of special elements in the /IDC_Logging/checkifdone.cgi ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28770</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28770</guid>
    <pubDate>Wed, 04 Mar 2026 07:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28770</strong></p>
  <p>Improper neutralization of special elements in the /IDC_Logging/checkifdone.cgi script in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver Web management Interface version 101 allows for XML Injection. The application reflects un-sanitized user input from the `file` parameter directly into a CDATA block, allowing an authenticated attacker to break out of the tag…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28770">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1554 – XML Injection (aka Blind XPath Injection) vulnerability in Drupal Central Authen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1554</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1554</guid>
    <pubDate>Wed, 04 Feb 2026 21:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1554</strong></p>
  <p>XML Injection (aka Blind XPath Injection) vulnerability in Drupal Central Authentication System (CAS) Server allows Privilege Escalation.This issue affects Central Authentication System (CAS) Server: from 0.0.0 before 2.0.3, from 2.1.0 before 2.1.2.</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1554">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-66258 – Stored Cross-Site Scripting via XML Injection in DB Electronica Telecomunicazion...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66258</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66258</guid>
    <pubDate>Wed, 26 Nov 2025 01:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-66258</strong></p>
  <p>Stored Cross-Site Scripting via XML Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Stored XSS via crafted filenames injected into patchlist.xml. User-controlled filenames are directly concatenated into `patchlist.xml` without encoding, allowing injection of malicious JavaSc…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66258">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-12921 – A vulnerability has been found in OpenClinica Community Edition up to 3.12.2/3.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12921</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12921</guid>
    <pubDate>Mon, 10 Nov 2025 00:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-12921</strong></p>
  <p>A vulnerability has been found in OpenClinica Community Edition up to 3.12.2/3.13. Affected by this issue is some unknown functionality of the file /ImportCRFData?action=confirm of the component CRF Data Import. Such manipulation of the argument xml_file leads to xml injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor w…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12921">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-7473 – Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7473</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7473</guid>
    <pubDate>Tue, 21 Oct 2025 11:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-7473</strong></p>
  <p>Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection.</p>
  <p><strong>CVSS:</strong> 5.2 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7473">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-54251 – Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an XML In...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54251</guid>
    <pubDate>Tue, 09 Sep 2025 17:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-54251</strong></p>
  <p>Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an XML Injection vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to manipulate XML queries and gain limited unauthorized write access.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24404 – XML Injection RCE by parse http sitemap xml response vulnerability in Apache Her...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24404</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24404</guid>
    <pubDate>Tue, 09 Sep 2025 10:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24404</strong></p>
  <p>XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat.             The attacker needs to have an authenticated account with access, and add monitor parsed by xml, returned special content can trigger the XML parsing vulnerability.  This issue affects Apache HertzBeat (incubating): before 1.7.0.  Users are recommended to upgrade to version 1.7.0, which fixes the is…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24404">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-9375 – XML Injection vulnerability in xmltodict allows Input Data Manipulation.
This is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9375</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9375</guid>
    <pubDate>Mon, 01 Sep 2025 17:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-9375</strong></p>
  <p>XML Injection vulnerability in xmltodict allows Input Data Manipulation. This issue affects xmltodict: from 0.14.2 before 0.15.1.  NOTE: the scope of this CVE is disputed by the vendor on the grounds that xmltodict.unparse() delegates element-name handling to Python's xml.sax.saxutils.XMLGenerator, and that XMLGenerator should be the component performing validation.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9375">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49538 – ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an XML ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49538</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49538</guid>
    <pubDate>Tue, 08 Jul 2025 21:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49538</strong></p>
  <p>ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an XML Injection vulnerability that could lead to arbitrary file system read. An attacker can exploit this issue by injecting crafted XML or XPath queries to access unauthorized files or lead to denial of service. Exploitation of this issue does not require user interaction, and attack must have access to shared secrets.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49538">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-32138 – Improper Restriction of XML External Entity Reference vulnerability in supsystic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32138</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32138</guid>
    <pubDate>Fri, 04 Apr 2025 16:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-32138</strong></p>
  <p>Improper Restriction of XML External Entity Reference vulnerability in supsystic Easy Google Maps google-maps-easy allows XML Injection.This issue affects Easy Google Maps: from n/a through <= 1.11.18.</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32138">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-25036 – Improper Restriction of XML External Entity Reference vulnerability in Jalios JP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25036</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25036</guid>
    <pubDate>Fri, 21 Mar 2025 20:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-25036</strong></p>
  <p>Improper Restriction of XML External Entity Reference vulnerability in Jalios JPlatform allows XML Injection.This issue affects all versions of JPlatform 10 before 10.0.8 (SP8).</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25036">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-42185 – BigFix Patch Download Plug-ins are affected by an insecure package which is susc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-42185</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-42185</guid>
    <pubDate>Thu, 23 Jan 2025 03:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-42185</strong></p>
  <p>BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML injection attacks.  This allows an attacker to exploit this vulnerability by injecting malicious XML content, which can lead to various issues including denial of service and unauthorized access.</p>
  <p><strong>CVSS:</strong> 2.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-42185">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-13190 – A vulnerability classified as critical was found in ZeroWdd myblog 1.0. This vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13190</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13190</guid>
    <pubDate>Wed, 08 Jan 2025 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-13190</strong></p>
  <p>A vulnerability classified as critical was found in ZeroWdd myblog 1.0. This vulnerability affects unknown code of the file src/main/resources/mapper/BlogMapper.xml. The manipulation of the argument findBlogList/getTotalBlogs leads to xml injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13190">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-50442 – Improper Restriction of XML External Entity Reference vulnerability in WP Royal ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-50442</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-50442</guid>
    <pubDate>Mon, 28 Oct 2024 12:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-50442</strong></p>
  <p>Improper Restriction of XML External Entity Reference vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows XML Injection.This issue affects Royal Elementor Addons: from n/a through <= 1.3.980.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-50442">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-7098 – Improper Restriction of XML External Entity Reference vulnerability in SFS Consu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7098</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7098</guid>
    <pubDate>Mon, 16 Sep 2024 15:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-7098</strong></p>
  <p>Improper Restriction of XML External Entity Reference vulnerability in SFS Consulting ww.Winsure allows XML Injection.  This issue affects ww.Winsure: before 4.6.2.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7098">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-34740 – In attributeBytesBase64 and attributeBytesHex of BinaryXmlSerializer.java, there...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34740</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34740</guid>
    <pubDate>Thu, 15 Aug 2024 22:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-34740</strong></p>
  <p>In attributeBytesBase64 and attributeBytesHex of BinaryXmlSerializer.java, there is a possible arbitrary XML injection due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34740">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-32173 – Unified Automation UaGateway AddServer XML Injection Denial-of-Service Vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32173</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32173</guid>
    <pubDate>Fri, 03 May 2024 02:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-32173</strong></p>
  <p>Unified Automation UaGateway AddServer XML Injection Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation UaGateway. Authentication is required to exploit this vulnerability when the product is in its default configuration.  The specific flaw exists within the implementation of the AddSe…</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32173">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-27328 – Parallels Desktop Toolgate XML Injection Local Privilege Escalation Vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-27328</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-27328</guid>
    <pubDate>Fri, 03 May 2024 02:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-27328</strong></p>
  <p>Parallels Desktop Toolgate XML Injection Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability.  The specific flaw exists within the Toolgate component. The is…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-27328">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-4245 – A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterU...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-4245</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-4245</guid>
    <pubDate>Mon, 25 Sep 2023 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-4245</strong></p>
  <p>A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comments for a --> sequence. This issue means that text contained in the command string could be interpreted as XML and allow for XML injection.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-4245">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36023 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36023</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36023</guid>
    <pubDate>Wed, 06 Sep 2023 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36023</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36023">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-46751 – Improper Restriction of XML External Entity Reference, XML Injection (aka Blind ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-46751</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-46751</guid>
    <pubDate>Mon, 21 Aug 2023 07:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-46751</strong></p>
  <p>Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache Ivy.This issue affects any version of Apache Ivy prior to 2.5.2.  When Apache Ivy prior to 2.5.2 parses XML files - either its own configuration, Ivy files or Apache Maven POMs - it will allow downloading external document type definitions and expand…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-46751">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38207 – Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38207</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38207</guid>
    <pubDate>Wed, 09 Aug 2023 08:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38207</strong></p>
  <p>Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) are affected by a XML Injection (aka Blind XPath Injection) vulnerability that could lead in minor arbitrary file system read. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38207">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-29289 – Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-29289</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-29289</guid>
    <pubDate>Thu, 15 Jun 2023 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-29289</strong></p>
  <p>Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an XML Injection vulnerability. An attacker with low privileges can trigger a specially crafted script to a security feature bypass. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29289">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22247 – Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are af...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22247</guid>
    <pubDate>Mon, 27 Mar 2023 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22247</strong></p>
  <p>Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an XML Injection vulnerability that could lead to arbitrary file system read. An unauthenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-35259 – XML Injection with Endpoint Manager 2022. 3 and below causing a download of a ma...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-35259</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-35259</guid>
    <pubDate>Mon, 05 Dec 2022 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-35259</strong></p>
  <p>XML Injection with Endpoint Manager 2022. 3 and below causing a download of a malicious file to run and possibly execute to gain unauthorized privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-35259">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-27233 – XML injection in the Quartus(R) Prime Programmer included in the Intel(R) Quartu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27233</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27233</guid>
    <pubDate>Fri, 11 Nov 2022 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-27233</strong></p>
  <p>XML injection in the Quartus(R) Prime Programmer included in the Intel(R) Quartus Prime Pro and Standard edition software may allow an unauthenticated user to potentially enable information disclosure via network access.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27233">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-34253 – Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-34253</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-34253</guid>
    <pubDate>Tue, 16 Aug 2022 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-34253</strong></p>
  <p>Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an XML Injection vulnerability in the Widgets Module. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34253">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32458 – Digiwin BPM has a XML External Entity Injection (XXE) vulnerability due to insuf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32458</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32458</guid>
    <pubDate>Wed, 20 Jul 2022 02:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32458</strong></p>
  <p>Digiwin BPM has a XML External Entity Injection (XXE) vulnerability due to insufficient validation for user input. An unauthenticated remote attacker can perform XML injection attack to access arbitrary system files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32458">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-25356 – Alt-N MDaemon Security Gateway through 8.5.0 allows SecurityGateway.dll?view=log...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-25356</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-25356</guid>
    <pubDate>Tue, 05 Apr 2022 02:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-25356</strong></p>
  <p>Alt-N MDaemon Security Gateway through 8.5.0 allows SecurityGateway.dll?view=login XML Injection.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-25356">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36033 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36033</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36033</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36033</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Module. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36033">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36028 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36028</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36028</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36028</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability when saving a configurable product. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36028">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36022 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36022</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36022</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36022</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36022">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36020 – Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36020</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36020</guid>
    <pubDate>Wed, 01 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36020</strong></p>
  <p>Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the 'City' field. An unauthenticated attacker can trigger a specially crafted script to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36020">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-37154 – In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37154</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37154</guid>
    <pubDate>Wed, 25 Aug 2021 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-37154</strong></p>
  <p>In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37154">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-21025 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21025</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21025</guid>
    <pubDate>Thu, 11 Feb 2021 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-21025</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to XML injection in the product layout updates. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21025">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-21019 – Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21019</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21019</guid>
    <pubDate>Thu, 11 Feb 2021 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-21019</strong></p>
  <p>Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to XML injection in the Widgets module. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21019">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-11535 – An issue was discovered in ONLYOFFICE Document Server 5.5.0. An attacker can cra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11535</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11535</guid>
    <pubDate>Wed, 15 Apr 2020 15:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-11535</strong></p>
  <p>An issue was discovered in ONLYOFFICE Document Server 5.5.0. An attacker can craft a malicious .docx file, and exploit XML injection to enter an attacker-controlled parameter into the x2t binary, to rewrite this binary and/or libxcb.so.1, and execute code on a victim's server.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11535">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2015-6970 – The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Camera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-6970</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-6970</guid>
    <pubDate>Tue, 18 Feb 2020 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2015-6970</strong></p>
  <p>The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows remote attackers to conduct XML injection attacks via the idstring parameter to rcp.xml.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-6970">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-16174 – An XML injection vulnerability was found in Limesurvey before 3.17.14 that allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16174</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16174</guid>
    <pubDate>Mon, 09 Sep 2019 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-16174</strong></p>
  <p>An XML injection vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to import specially crafted XML files and execute code or compromise data integrity.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16174">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-14277 – Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API confi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14277</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14277</guid>
    <pubDate>Fri, 26 Jul 2019 04:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-14277</strong></p>
  <p>Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is vulnerable to unauthenticated blind XML injection (and XXE) in the resetPassword functionality via the REST API. This vulnerability can lead to local file disclosure, DoS, or URI invocation attacks (i.e., SSRF with resultant remote code execution). NOTE: The vendor disputes this issues as not being a vuln…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14277">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-1010017 – libnmap &lt; v0.6.3 is affected by: XML Injection. The impact is: Denial of service...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-1010017</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-1010017</guid>
    <pubDate>Mon, 15 Jul 2019 03:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-1010017</strong></p>
  <p>libnmap < v0.6.3 is affected by: XML Injection. The impact is: Denial of service (DoS) by consuming resources. The component is: XML Parsing. The attack vector is: Specially crafted XML payload.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-1010017">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-12787 – An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BET...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12787</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12787</guid>
    <pubDate>Mon, 10 Jun 2019 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-12787</strong></p>
  <p>An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA. There is a command injection in HNAP1 SetWanSettings via an XML injection of the value of the Gateway key.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12787">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-12786 – An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BET...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12786</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12786</guid>
    <pubDate>Mon, 10 Jun 2019 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-12786</strong></p>
  <p>An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA. There is a command injection in HNAP1 SetWanSettings via an XML injection of the value of the IPAddress key.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12786">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-9362 – ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Confi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-9362</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-9362</guid>
    <pubDate>Mon, 25 Mar 2019 16:29:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-9362</strong></p>
  <p>ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-9362">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-16784 – DedeCMS 5.7 SP2 allows XML injection, and resultant remote code execution, via a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-16784</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-16784</guid>
    <pubDate>Fri, 21 Sep 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-16784</strong></p>
  <p>DedeCMS 5.7 SP2 allows XML injection, and resultant remote code execution, via a "<file type='file' name='../" substring.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-16784">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-16785 – XML injection vulnerability exists in the file of DedeCMS V5.7 SP2 version, whic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-16785</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-16785</guid>
    <pubDate>Wed, 19 Sep 2018 15:29:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-16785</strong></p>
  <p>XML injection vulnerability exists in the file of DedeCMS V5.7 SP2 version, which can be utilized by attackers to create script file to obtain webshell</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-16785">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1000632 – dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1000632</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1000632</guid>
    <pubDate>Mon, 20 Aug 2018 19:31:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1000632</strong></p>
  <p>dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000632">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1000526 – Openpsa contains a XML Injection vulnerability in RSS file upload feature that c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1000526</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1000526</guid>
    <pubDate>Tue, 26 Jun 2018 16:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1000526</strong></p>
  <p>Openpsa contains a XML Injection vulnerability in RSS file upload feature that can result in Remote denial of service. This attack appear to be exploitable via Specially crafted XML file. This vulnerability appears to have been fixed in after commit 4974a26.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000526">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1000090 – textpattern version version 4.6.2 contains a XML Injection vulnerability in Impo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1000090</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1000090</guid>
    <pubDate>Tue, 13 Mar 2018 15:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1000090</strong></p>
  <p>textpattern version version 4.6.2 contains a XML Injection vulnerability in Import XML feature that can result in Denial of service in context to the web server by exhausting server memory resources. This attack appear to be exploitable via Uploading a specially crafted XML file.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000090">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-7429 – The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to conduct ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-7429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-7429</guid>
    <pubDate>Thu, 14 Sep 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-7429</strong></p>
  <p>The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to conduct XML injection attacks via the url parameter to plugin_googlemap2_proxy.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-7429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-10603 – An XML injection vulnerability in Junos OS CLI can allow a locally authenticated...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-10603</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-10603</guid>
    <pubDate>Mon, 17 Jul 2017 13:18:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-10603</strong></p>
  <p>An XML injection vulnerability in Junos OS CLI can allow a locally authenticated user to elevate privileges and run arbitrary commands as the root user. This issue was found during internal product security testing. Affected releases are Juniper Networks Junos OS 15.1X53 prior to 15.1X53-D47, 15.1 prior to 15.1R3. Junos versions prior to 15.1 are not affected. No other Juniper Networks products o…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-10603">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-6662 – A vulnerability in the web-based user interface of Cisco Prime Infrastructure (P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-6662</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-6662</guid>
    <pubDate>Mon, 26 Jun 2017 07:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-6662</strong></p>
  <p>A vulnerability in the web-based user interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker read and write access to information stored in the affected system as well as perform remote code execution. The attacker must have valid user credentials. The vulnerability is due to improper handling of XML External Enti…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-6662">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-2932 – IBM BigFix Remote Control before 9.1.3 allows remote attackers to conduct XML in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-2932</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-2932</guid>
    <pubDate>Wed, 30 Nov 2016 11:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-2932</strong></p>
  <p>IBM BigFix Remote Control before 9.1.3 allows remote attackers to conduct XML injection attacks via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-2932">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-6011 – Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge before 2015...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-6011</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-6011</guid>
    <pubDate>Mon, 28 Sep 2015 02:59:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-6011</strong></p>
  <p>Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge before 2015-01-08 allows remote attackers to conduct XML injection attacks via (1) the id parameter to unapi.php or (2) the stylesheet parameter to sru.php.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-6011">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-6193 – IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF14 and 8.5.0 before CF04, when the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-6193</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-6193</guid>
    <pubDate>Fri, 19 Dec 2014 02:59:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-6193</strong></p>
  <p>IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF14 and 8.5.0 before CF04, when the Managed Pages setting is enabled, allows remote authenticated users to write to pages via an XML injection attack.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-6193">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-2161 – XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizz...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2161</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2161</guid>
    <pubDate>Tue, 20 Aug 2013 22:55:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-2161</strong></p>
  <p>XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift responses via an account name.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2161">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-2596 – The XPath functionality in unspecified web applications in Siemens WinCC 7.0 SP3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-2596</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-2596</guid>
    <pubDate>Fri, 08 Jun 2012 18:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-2596</strong></p>
  <p>The XPath functionality in unspecified web applications in Siemens WinCC 7.0 SP3 before Update 2 does not properly handle special characters in parameters, which allows remote authenticated users to read or modify settings via a crafted URL, related to an "XML injection" attack.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-2596">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-2150 – The SmarterTools SmarterStats 6.0 web server does not properly validate string d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-2150</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-2150</guid>
    <pubDate>Fri, 20 May 2011 22:55:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-2150</strong></p>
  <p>The SmarterTools SmarterStats 6.0 web server does not properly validate string data that is intended for storage in an XML document, which allows remote attackers to cause a denial of service (parsing error and daemon pause) via vectors involving (1) certain cookies in a SiteInfoLookup action to Admin/frmSites.aspx, or certain (2) cookies or (3) parameters to (a) Client/frmViewOverviewReport.aspx…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-2150">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-2079 – MediaCAST 8 and earlier allows remote attackers to have an unspecified impact vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-2079</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-2079</guid>
    <pubDate>Tue, 10 May 2011 19:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-2079</strong></p>
  <p>MediaCAST 8 and earlier allows remote attackers to have an unspecified impact via a (1) CP_RIGHTSOURCE or (2) bdclient_Inventive cookie to the default URI under inventivex/managetraining/, related to an "XML injection" issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-2079">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-3260 – oxf/xml/xerces/XercesSAXParserFactoryImpl.java in the xforms-server component in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-3260</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-3260</guid>
    <pubDate>Wed, 27 Apr 2011 00:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-3260</strong></p>
  <p>oxf/xml/xerces/XercesSAXParserFactoryImpl.java in the xforms-server component in the XForms service in Orbeon Forms before 3.9 does not properly restrict DTDs in Ajax requests, which allows remote attackers to read arbitrary files or send HTTP requests to intranet servers via an entity declaration in conjunction with an entity reference, related to an "XML injection" issue.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-3260">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-5024 – Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-5024</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-5024</guid>
    <pubDate>Thu, 13 Nov 2008 11:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-5024</strong></p>
  <p>Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection attacks via the default namespace in an E4X document.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-5024">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
