Skip to main content

Threats Tagged 'cwe-91'

View all threats tagged with 'cwe-91'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-91

Threats Tagged 'cwe-91'

Click on any threat for detailed analysis and mitigation recommendations

ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to an XML Injection vulnerability in the Rule Tracking Compare Policies feature.

Join the discussion

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an XML injection. A successful exploit of this vulnerability might lead to data tampering and denial of service.

Join the discussion

IBM webMethods Integration Server 11.1 is affected by an XML external entity (XXE) injection vulnerability, also known as Blind XPath Injection (CWE-91). This vulnerability allows a remote attacker with limited privileges to exploit XML processing to potentially expose sensitive information or cause resource exhaustion. The vulnerability has a high severity rating with a CVSS score of 7.8.

Join the discussion

CVE-2026-48590 is an XML Injection vulnerability in the joshnuss xml_builder library affecting versions from 0.0.1 up to but not including 2.4.1. The vulnerability arises because element names, attribute names, and doctype identifiers are inserted into XML output without proper validation or escaping of special characters. This allows an attacker who can control these inputs to inject arbitrary XML markup, potentially leading to content spoofing or manipulation of the XML document structure. The CVSS score is low (2.1), indicating limited impact and attack complexity.

Join the discussion

CVE-2026-47080 is an XML Injection vulnerability in the joshnuss xml_builder library affecting versions from 0.0.7 up to but not including 2.4.1. The flaw arises because the escape/1 function does not properly handle embedded CDATA section terminators (]]>) in user-supplied input, allowing an attacker to prematurely close CDATA sections and inject arbitrary XML content. This can lead to content spoofing and XML injection attacks. The vulnerability has a low CVSS 4.0 score of 2.1, indicating limited impact and complexity.

Join the discussion

Astro is a web framework for content-driven websites. In versions 1.0.0 through 4.0.18, the source.title and enclosure.type item fields in packages/astro-rss/src/index.ts are interpolated directly into XML template strings without XML-character escaping before being parsed by fast-xml-parser. Both fields are validated only as z.string(), placing no restriction on XML special characters. An attacker who controls these values can inject arbitrary XML into the generated RSS feed: a value containing " can break out of an attribute (as with enclosure.type), and a value containing </source> can close an element early and inject additional nodes (as with source.title). This corrupts feed structure, injects false metadata (for example, a fake <link> pointing to a malicious URL), and can cause feed readers to misparse or display attacker-controlled content. In SSR mode (output: 'server'), the poisoned feed is served on every request to all subscribers. This issue has been fixed in version 4.0.19.

Join the discussion

Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.

Join the discussion

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's self-hosted SAML application IdP built the signed SAML response and assertion by string-substituting user-controlled profile attributes such as name, email, and custom attribute-mapping values into element-text placeholders of a SAML XML template using samlify 2.10.0, which left those placeholders unescaped. An authenticated low-privilege user could place XML markup in a profile attribute so Logto signed a forged SAML attribute, such as an arbitrary role, allowing privilege escalation at relying Service Providers that authorize on SAML attributes. This issue is fixed in version 1.41.0.

Join the discussion

Guzzle Services versions prior to 1.5.3 improperly serialize scalar XML element values containing the CDATA terminator ']]>', causing early CDATA section closure and injection of attacker-controlled XML elements in outgoing requests. This vulnerability affects applications that serialize untrusted input into XML element text parameters with location: xml, potentially allowing alteration of operation semantics or injection of conflicting elements. The issue does not affect response parsing directly and is fixed in version 1.5.3 by safely handling embedded CDATA terminators.

Join the discussion

CVE-2026-46490 is an XML Injection vulnerability in the Node.js library samlify prior to version 2.13.0. The issue arises because samlify escapes only attribute contexts during template substitution, but does not escape values inserted into element text such as <saml:AttributeValue>. This allows an attacker to inject XML markup into attribute values, resulting in additional <saml:Attribute> elements inside signed assertions. Consequently, the Identity Provider (IdP) signs tampered assertions, and the Service Provider (SP) accepts injected attributes as trusted, enabling privilege escalation when attributes control authorization. The vulnerability has been patched in samlify version 2.13.0.

Join the discussion

Showing 1 to 10 of 23 results

Filters:Tag: cwe-91
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses