CWE-91: aka Blind XPath Injection
The product does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system.
70 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-42374 — XML injection in SAP BEx Web Java Runtime Export Web Service
- CVE-2024-47113 — IBM ICP - Voice Gateway XML injection
- CVE-2024-28109 — Potential XSLT injection vulnerability when using policy files
- CVE-2024-53675 — An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose in
- CVE-2025-49538 — ColdFusion | XML Injection (aka Blind XPath Injection) (CWE-91)
- CVE-2024-53674 — An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose in
- CVE-2026-83618 — xmldom: requireWellFormed DocType publicId/systemId validation is bypassable via an embedded line terminator
- CVE-2026-83608 — xmldom: DocType `name` Injection Bypasses requireWellFormed
- CVE-2026-83605 — xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed
- CVE-2026-41675 — xmldom: XML node injection through unvalidated processing instruction serialization
- CVE-2026-41674 — xmldom: XML injection through unvalidated DocumentType serialization
- CVE-2026-41672 — xmldom: XML node injection through unvalidated comment serialization
- CVE-2026-83617 — xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminator
- CVE-2026-83616 — xmldom: Processing Instruction Target Injection Bypasses requireWellFormed
- CVE-2026-83609 — xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the default serialization path
- CVE-2026-83607 — xmldom: Element name injection via createElement() bypasses requireWellFormed
- CVE-2026-46490 — samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions
- CVE-2026-40165 — authentik: SAML NameID XML Comment Injection Enables Authentication Bypass via Identifier Truncation
- CVE-2026-55789 — Logto: SAML IdP injects user-controlled profile attributes raw into signed assertions, allowing privilege escalation at relying Service Providers
- CVE-2025-1545 — WatchGuard Firebox XPath Injection Vulnerability in Web CGI
Recently published
- CVE-2026-83618 — xmldom: requireWellFormed DocType publicId/systemId validation is bypassable via an embedded line terminator
- CVE-2026-83617 — xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminator
- CVE-2026-83616 — xmldom: Processing Instruction Target Injection Bypasses requireWellFormed
- CVE-2026-83609 — xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the default serialization path
- CVE-2026-83608 — xmldom: DocType `name` Injection Bypasses requireWellFormed
- CVE-2026-83607 — xmldom: Element name injection via createElement() bypasses requireWellFormed
- CVE-2026-83605 — xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed
- CVE-2026-48590 — Element and Attribute Names Injected Verbatim into XML Output in xml_builder
- CVE-2026-47080 — CDATA Section Breakout via Unsanitised ]]> in xml_builder
- CVE-2026-24329 — Wildfly-core: wildfly core: denial of service via malformed payload injection by an authenticated administrative user.
- CVE-2026-59728 — @astrojs/rss: XML Injection via Unescaped RSS Feed Fields
- CVE-2026-15037 — XML injection vulnerability in QDom comment, CDATA and processing-instruction serialization
- CVE-2026-55789 — Logto: SAML IdP injects user-controlled profile attributes raw into signed assertions, allowing privilege escalation at relying Service Providers
- CVE-2026-53723 — guzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injection via CDATA Terminator
- CVE-2026-46490 — samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions
- CVE-2026-47273 — pam_usb: XPath injection via PAM-supplied identifiers in pam_usb configuration queries
- CVE-2026-40165 — authentik: SAML NameID XML Comment Injection Enables Authentication Bypass via Identifier Truncation
- CVE-2026-44664 — fast-xml-builder: Comment Value bypass regex
- CVE-2026-44665 — fast-xml-builder: Attribute values with unwanted quotes can bypass malicious or unwanted attributes
- CVE-2026-41650 — fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters