CWE-91: CWE-91

26
Total CVEs
3
Critical
17
High
7.5
Avg CVSS

Yearly Trend

2026
1
2025
9
2024
4
2023
5
2022
2

Top Affected Vendors

1 Adobe 3
2 Ibm 2
3 Apache 2
4 Fonttools 1
5 Ghostxbh 1
6 Jtenman 1
7 Openmage 1
8 Parallels 1
9 Reportlab 1
10 Broadcom 1

All CWE-91 CVEs (26)

CVE-2019-19450
9.8

CVE-2019-19450 is a critical remote code execution vulnerability in ReportLab's paraparser module. Attackers can execute arbitrary Python code by craf...

Sep 20, 2023
CVE-2020-29128
9.8

CVE-2020-29128 is an XML External Entity (XXE) vulnerability in petl versions before 1.68 that allows attackers to read arbitrary files, conduct serve...

Nov 26, 2020
CVE-2021-38948
9.1

IBM InfoSphere Information Server 11.7 has an XML External Entity Injection (XXE) vulnerability that allows attackers to read sensitive files from the...

Nov 2, 2021
CVE-2025-24404
8.8

This vulnerability allows authenticated attackers to execute arbitrary code on Apache HertzBeat servers by injecting malicious XML into HTTP sitemap r...

Sep 9, 2025
CVE-2021-2322
8.8

CVE-2021-2322 is a critical vulnerability in OpenGrok web application that allows authenticated attackers with low privileges to completely compromise...

Jun 23, 2021
CVE-2024-42374
8.2

This XML injection vulnerability in SAP BEx Web Java Runtime Export Web Service allows attackers to retrieve sensitive information from SAP ADS system...

Aug 13, 2024
CVE-2022-46751
8.2

Apache Ivy versions before 2.5.2 have an XML External Entity (XXE) vulnerability that allows attackers to read arbitrary files, access internal resour...

Aug 21, 2023
CVE-2021-36020
8.2

This CVE describes an XML injection vulnerability in Magento Commerce's 'City' field that allows unauthenticated attackers to execute arbitrary code r...

Sep 1, 2021
CVE-2025-25589
8.1

This XXE injection vulnerability in yimioa's XML parsing component allows attackers to execute arbitrary code by uploading malicious XML files. It aff...

Mar 18, 2025
CVE-2024-47113
8.1

This XML injection vulnerability in IBM ICP - Voice Gateway allows remote attackers to send specially crafted XML statements to view or modify informa...

Jan 18, 2025
CVE-2024-28109
8.1

CVE-2024-28109 is a remote code execution vulnerability in veraPDF-library that allows attackers to execute arbitrary code by exploiting XSL transform...

Mar 28, 2024
CVE-2023-46214
8.0

This vulnerability allows remote code execution on Splunk Enterprise instances by uploading malicious XSLT files. Attackers can execute arbitrary code...

Nov 16, 2023
CVE-2023-27328
7.8

This vulnerability allows local attackers on Parallels Desktop guest systems to escalate privileges by exploiting XML injection in the Toolgate compon...

May 3, 2024
CVE-2025-1545
7.5

An XPath injection vulnerability in WatchGuard Fireware OS allows remote unauthenticated attackers to extract sensitive configuration data from Firebo...

Dec 4, 2025
CVE-2023-22247
7.5

CVE-2023-22247 is an XML injection vulnerability in Adobe Commerce that allows unauthenticated attackers to read arbitrary files from the server. This...

Mar 27, 2023
CVE-2022-33739
7.5

CVE-2022-33739 is an XML External Entity (XXE) vulnerability in CA Clarity PPM that allows remote attackers to read arbitrary files on the server. Thi...

Jun 16, 2022
CVE-2021-27777
7.5

CVE-2021-27777 is an XML External Entity (XXE) injection vulnerability in HCL Domino that allows attackers to read arbitrary files from the server fil...

May 12, 2022
CVE-2024-53675
7.3

An XML external entity injection vulnerability in HPE Insight Remote Support allows remote attackers to read arbitrary files from the server filesyste...

Nov 26, 2024
CVE-2019-25137
7.2

This vulnerability allows authenticated administrators in Umbraco CMS to execute arbitrary code remotely via XSLT processing. Attackers can inject mal...

May 18, 2023
CVE-2021-32758
7.2

This vulnerability allows authenticated admin users in OpenMage Magento LTS to execute arbitrary commands through layout XML manipulation. It affects ...

Aug 27, 2021
CVE-2025-60833
6.5

This XML External Entity (XXE) vulnerability in the uzy-ssm-mall e-commerce platform allows attackers to execute arbitrary code by sending specially c...

Oct 8, 2025
CVE-2025-66034
6.3

This vulnerability in fontTools allows arbitrary file write leading to remote code execution when processing malicious .designspace files. It affects ...

Nov 29, 2025
CVE-2025-47184
5.3

An authenticated attacker can exploit an XML external entities (XXE) injection vulnerability in Exagrid EX10's /init API endpoint to read sensitive fi...

Aug 21, 2025
CVE-2025-7473
5.2

CVE-2025-7473 is an XML injection vulnerability in Zohocorp ManageEngine EndPoint Central that allows attackers to manipulate XML data processing. Thi...

Oct 21, 2025
CVE-2025-54251
4.3

Adobe Experience Manager versions 6.5.23.0 and earlier contain an XML injection vulnerability that allows low-privileged attackers to manipulate XML q...

Sep 9, 2025
CVE-2026-1554
4.2

This XML Injection vulnerability in Drupal CAS Server allows attackers to manipulate XPath queries to escalate privileges. It affects Drupal sites usi...

Feb 4, 2026

About CWE-91 (CWE-91)

Our database tracks 26 CVEs classified as CWE-91, with 3 rated critical and 17 rated high severity. The average CVSS score for CWE-91 vulnerabilities is 7.5.

External reference: View CWE-91 on MITRE CWE →

Monitor CWE-91 Vulnerabilities

Get alerted when new CWE-91 CVEs affect your infrastructure.

Start Monitoring Free