The product accepts XML from an untrusted source but does not validate the XML against the proper schema.
Volume of CVEs assigned to CWE-112 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-68493HIGH Missing XML Validation vulnerability in Apache Struts, Apache Struts.
This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0.
Users ar | Jan 11, 2026 | 8.1 | 45 | NO | NO |
CVE-2022-28213HIGH When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the XML document accepted from an u | Apr 12, 2022 | 8.1 | 35 | NO | YES |
CVE-2021-1359HIGH A vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform command injection a | Jul 8, 2021 | 8.8 | 28 | NO | NO |
CVE-2023-40310HIGH SAP PowerDesigner Client - version 16.7, does not sufficiently validate BPMN2 XML document imported from an untrusted source. As a result, URLs of external entities in BPMN2 file, | Oct 10, 2023 | 7.5 | 22 | NO | NO |
CVE-2020-1975HIGH Missing XML validation vulnerability in the PAN-OS web interface on Palo Alto Networks PAN-OS software allows authenticated users to inject arbitrary XML that results in privilege | Feb 12, 2020 | 8.8 | 22 | NO | NO |
CVE-2021-27780MEDIUM The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment. | May 27, 2022 | 5.3 | 20 | NO | NO |
A flaw was found in Keycloak's SAML brokering functionality. When Keycloak is configured as a client in a Security Assertion Markup Language (SAML) setup, it fails to validate the | Jan 26, 2026 | 3.1 | 14 | NO | NO |
CVE-2020-27282MEDIUM In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, an XML validation vulnerability in the ventilator allows privileged attackers with physical access to render the dev | Mar 15, 2021 | 4.3 | 14 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.