Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
pam_usb: XPath injection via PAM-supplied identifiers in pam_usb configuration queries
authentik: SAML NameID XML Comment Injection Enables Authentication Bypass via Identifier Truncation
fast-xml-builder: Comment Value bypass regex
fast-xml-builder: Attribute values with unwanted quotes can bypass malicious or unwanted attributes
fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters
xmldom: XML node injection through unvalidated processing instruction serialization
xmldom: XML injection through unvalidated DocumentType serialization
xmldom: XML node injection through unvalidated comment serialization
traccar allows XML injection in KML and GPX exports
Kirby has XML injection in its XML creator toolkit
xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion
XML injection In /IDC_Logging/checkifdone.cgi Endpoint On IDC SFX Web Management Interface Version 101
Central Authentication System (CAS) Server - Less critical - XML Element Injection - SA-CONTRIB-2026-007
Wondershare FamiSafe 1.0 - 'FSService' Unquoted Service Path
WatchGuard Firebox XPath Injection Vulnerability in Web CGI
fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib
OpenClinica Community Edition CRF Data Import ImportCRFData xml injection
XML Injection
Adobe Experience Manager | XML Injection (aka Blind XPath Injection) (CWE-91)
Apache HertzBeat (incubating): RCE by parse http sitemap xml response
Showing 1 - 20 of 1,000+ results