The product does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system.
Volume of CVEs assigned to CWE-91 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
129 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-0646CRITICAL A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'. | Jan 14, 2020 | 9.8 | 99 | YES | YES |
CVE-2023-46214HIGH In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize extensible stylesheet language transformations (XSLT) that users supply. This means | Nov 16, 2023 | 8.8 | 84 | NO | YES |
CVE-2023-27253HIGH A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the cont | Mar 17, 2023 | 8.8 | 84 | NO | YES |
CVE-2024-53675HIGH An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases. | Nov 26, 2024 | 7.5 | 70 | NO | NO |
CVE-2023-43187CRITICAL A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers to execute arbitrary code via crafted X | Sep 27, 2023 | 9.8 | 61 | NO | YES |
CVE-2024-53674HIGH An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases. | Nov 26, 2024 | 7.5 | 47 | NO | NO |
CVE-2015-6970CRITICAL The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows remote attackers to conduct XML injection attacks via the ids | Feb 18, 2020 | 9.8 | 43 | NO | YES |
CVE-2018-19277HIGH securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx file | Nov 14, 2018 | 8.8 | 42 | NO | YES |
CVE-2016-6272HIGH XPath injection vulnerability in Epic MyChart allows remote attackers to access contents of an XML document containing static display strings, such as field labels, via the topic p | Feb 20, 2018 | 7.5 | 38 | NO | YES |
CVE-2026-55789HIGH Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's self-hosted SAML application IdP built the signed SAML response and assertion by | Jul 10, 2026 | 8.5 | 37 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.