CWE-643: XPath Injection
The product uses external input to dynamically construct an XPath expression used to retrieve data from an XML database, but it does not neutralize or incorrectly neutralizes that input. This allows an attacker to control the structure of the query.
14 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-39565 — Junos OS: J-Web: An unauthenticated, network-based attacker can perform XPATH injection attack against a device.
- CVE-2026-44962 — Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied
- CVE-2026-9390 — XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup
- CVE-2026-40699 — BIG-IP Configuration utility vulnerability
- CVE-2025-11844 — XPath Injection in Hugging Face Smolagents search_item_ctrl_f Function
- CVE-2025-20218 — Cisco Secure Firepower Management Center Software XPATH Injection Vulnerability
- CVE-2026-24343 — Apache HertzBeat: Uncontrolled Resource Consumption via Crafted XPath Expressions
Recently published
- CVE-2026-9390 — XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup
- CVE-2026-44962 — Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied
- CVE-2026-40699 — BIG-IP Configuration utility vulnerability
- CVE-2026-24343 — Apache HertzBeat: Uncontrolled Resource Consumption via Crafted XPath Expressions
- CVE-2025-11844 — XPath Injection in Hugging Face Smolagents search_item_ctrl_f Function
- CVE-2025-20218 — Cisco Secure Firepower Management Center Software XPATH Injection Vulnerability
- CVE-2024-39565 — Junos OS: J-Web: An unauthenticated, network-based attacker can perform XPATH injection attack against a device.