Vulnerabilities > XML Injection (aka Blind XPath Injection)

DATE CVE VULNERABILITY TITLE RISK
2023-01-24 CVE-2023-22485 XML Injection (aka Blind XPath Injection) vulnerability in Github Cmark-Gfm
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C.
network
low complexity
github CWE-91
5.3
2022-12-22 CVE-2021-4140 It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox.
network
low complexity
CWE-91
critical
10.0
2022-12-05 CVE-2022-35259 XML Injection (aka Blind XPath Injection) vulnerability in Ivanti Endpoint Manager
XML Injection with Endpoint Manager 2022.
local
low complexity
ivanti CWE-91
7.8
2022-11-11 CVE-2022-27233 XML Injection (aka Blind XPath Injection) vulnerability in Intel Quartus Prime
XML injection in the Quartus(R) Prime Programmer included in the Intel(R) Quartus Prime Pro and Standard edition software may allow an unauthenticated user to potentially enable information disclosure via network access.
network
low complexity
intel CWE-91
7.5
2022-10-18 CVE-2022-22243 XML Injection (aka Blind XPath Injection) vulnerability in Juniper Junos
An XPath Injection vulnerability due to Improper Input Validation in the J-Web component of Juniper Networks Junos OS allows an authenticated attacker to add an XPath command to the XPath stream, which may allow chaining to other unspecified vulnerabilities, leading to a partial loss of confidentiality.
network
low complexity
juniper CWE-91
4.3
2022-10-18 CVE-2022-22244 XML Injection (aka Blind XPath Injection) vulnerability in Juniper Junos
An XPath Injection vulnerability in the J-Web component of Juniper Networks Junos OS allows an unauthenticated attacker sending a crafted POST to reach the XPath channel, which may allow chaining to other unspecified vulnerabilities, leading to a partial loss of confidentiality.
network
low complexity
juniper CWE-91
5.3
2022-08-16 CVE-2022-34253 XML Injection (aka Blind XPath Injection) vulnerability in multiple products
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an XML Injection vulnerability in the Widgets Module.
network
low complexity
adobe magento CWE-91
7.2
2022-06-16 CVE-2022-33739 XML Injection (aka Blind XPath Injection) vulnerability in Broadcom CA Clarity 15.9.0
CA Clarity 15.8 and below and 15.9.0 contain an insecure XML parsing vulnerability that could allow a remote attacker to potentially view the contents of any file on the system.
network
low complexity
broadcom CWE-91
5.0
2022-05-18 CVE-2022-22784 XML Injection (aka Blind XPath Injection) vulnerability in Zoom Meetings
The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly parse XML stanzas in XMPP messages.
network
low complexity
zoom CWE-91
5.5
2022-05-03 CVE-2022-20729 XML Injection (aka Blind XPath Injection) vulnerability in Cisco Firepower Threat Defense
A vulnerability in CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to inject XML into the command parser.
local
low complexity
cisco CWE-91
7.8