CWE-91: CWE-91
Yearly Trend
Top Affected Vendors
All CWE-91 CVEs (26)
CVE-2019-19450 is a critical remote code execution vulnerability in ReportLab's paraparser module. Attackers can execute arbitrary Python code by craf...
Sep 20, 2023CVE-2020-29128 is an XML External Entity (XXE) vulnerability in petl versions before 1.68 that allows attackers to read arbitrary files, conduct serve...
Nov 26, 2020IBM InfoSphere Information Server 11.7 has an XML External Entity Injection (XXE) vulnerability that allows attackers to read sensitive files from the...
Nov 2, 2021This vulnerability allows authenticated attackers to execute arbitrary code on Apache HertzBeat servers by injecting malicious XML into HTTP sitemap r...
Sep 9, 2025CVE-2021-2322 is a critical vulnerability in OpenGrok web application that allows authenticated attackers with low privileges to completely compromise...
Jun 23, 2021This XML injection vulnerability in SAP BEx Web Java Runtime Export Web Service allows attackers to retrieve sensitive information from SAP ADS system...
Aug 13, 2024Apache Ivy versions before 2.5.2 have an XML External Entity (XXE) vulnerability that allows attackers to read arbitrary files, access internal resour...
Aug 21, 2023This CVE describes an XML injection vulnerability in Magento Commerce's 'City' field that allows unauthenticated attackers to execute arbitrary code r...
Sep 1, 2021This XXE injection vulnerability in yimioa's XML parsing component allows attackers to execute arbitrary code by uploading malicious XML files. It aff...
Mar 18, 2025This XML injection vulnerability in IBM ICP - Voice Gateway allows remote attackers to send specially crafted XML statements to view or modify informa...
Jan 18, 2025CVE-2024-28109 is a remote code execution vulnerability in veraPDF-library that allows attackers to execute arbitrary code by exploiting XSL transform...
Mar 28, 2024This vulnerability allows remote code execution on Splunk Enterprise instances by uploading malicious XSLT files. Attackers can execute arbitrary code...
Nov 16, 2023This vulnerability allows local attackers on Parallels Desktop guest systems to escalate privileges by exploiting XML injection in the Toolgate compon...
May 3, 2024An XPath injection vulnerability in WatchGuard Fireware OS allows remote unauthenticated attackers to extract sensitive configuration data from Firebo...
Dec 4, 2025CVE-2023-22247 is an XML injection vulnerability in Adobe Commerce that allows unauthenticated attackers to read arbitrary files from the server. This...
Mar 27, 2023CVE-2022-33739 is an XML External Entity (XXE) vulnerability in CA Clarity PPM that allows remote attackers to read arbitrary files on the server. Thi...
Jun 16, 2022CVE-2021-27777 is an XML External Entity (XXE) injection vulnerability in HCL Domino that allows attackers to read arbitrary files from the server fil...
May 12, 2022An XML external entity injection vulnerability in HPE Insight Remote Support allows remote attackers to read arbitrary files from the server filesyste...
Nov 26, 2024This vulnerability allows authenticated administrators in Umbraco CMS to execute arbitrary code remotely via XSLT processing. Attackers can inject mal...
May 18, 2023This vulnerability allows authenticated admin users in OpenMage Magento LTS to execute arbitrary commands through layout XML manipulation. It affects ...
Aug 27, 2021This XML External Entity (XXE) vulnerability in the uzy-ssm-mall e-commerce platform allows attackers to execute arbitrary code by sending specially c...
Oct 8, 2025This vulnerability in fontTools allows arbitrary file write leading to remote code execution when processing malicious .designspace files. It affects ...
Nov 29, 2025An authenticated attacker can exploit an XML external entities (XXE) injection vulnerability in Exagrid EX10's /init API endpoint to read sensitive fi...
Aug 21, 2025CVE-2025-7473 is an XML injection vulnerability in Zohocorp ManageEngine EndPoint Central that allows attackers to manipulate XML data processing. Thi...
Oct 21, 2025Adobe Experience Manager versions 6.5.23.0 and earlier contain an XML injection vulnerability that allows low-privileged attackers to manipulate XML q...
Sep 9, 2025This XML Injection vulnerability in Drupal CAS Server allows attackers to manipulate XPath queries to escalate privileges. It affects Drupal sites usi...
Feb 4, 2026About CWE-91 (CWE-91)
Our database tracks 26 CVEs classified as CWE-91, with 3 rated critical and 17 rated high severity. The average CVSS score for CWE-91 vulnerabilities is 7.5.
External reference: View CWE-91 on MITRE CWE →
Monitor CWE-91 Vulnerabilities
Get alerted when new CWE-91 CVEs affect your infrastructure.
Start Monitoring Free