Backslash Vulnerability Database XML Injection (aka Blind XPath Injection)

XML Injection (aka Blind XPath Injection)

CWE-91

Overtime trend (NVD)

CVSS severity (NVD, All Time)

Per technology (GHSA, All time)

  • 41%-Composer
  • 32%-Maven
  • 16%-Pip
  • 9%-Others

Short description

The product does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system.

Extended description

Best practices to prevent this CWE

  • LinkedIn Icon
  • Facebook Icon
  • X Icon
  • Link Icon