XML is a data-serialization standard rather than a traditional software product, and its CVE footprint reflects vulnerabilities in implementations and parsers rather than a discrete vendor offering. The observed weaknesses span parsing and validation issues characteristic of XML processing across diverse applications and libraries. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xml over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-40934CRITICAL XML-Sig versions 0.27 through 0.67 for Perl incorrectly validates XML files if signatures are omitted.
An attacker can remove the signature from the XML document to make it pass t | Nov 26, 2025 | 9.3 | 28 | NO | NO |
CVE-2012-1102HIGH It was discovered that the XML::Atom Perl module before version 0.39 did not disable external entities when parsing XML from potentially untrusted sources. This may allow attackers | Jul 9, 2021 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xml.
Media articles that mention a CVE ID that affects a product developed by Xml — matched by CVE ID, not by vendor name.