https://advisories.gitlab.com/composer/magento/project-community-edition/CVE-2021-36020/
Magento XML Injection vulnerability in the 'City' field | GitLab Advisory Database (GLAD)
CVE-2021-36020 Magento XML Injection vulnerability in the 'City' field: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and...
in the cityxml injectionmagentovulnerabilityfield
https://cvefeed.io/vuln/detail/CVE-2019-11257
CVE-2019-11257 - General Dynamics Fidelis XPS XML Injection
Nov 7, 2023 - Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability...
general dynamicsxml injectioncvefidelisxps
https://devhub.checkmarx.com/cve-details/cve-2018-2477/
XML Injection (aka Blind XPath Injection) - CVE-2018-2477 - DevHub
May 9, 2023 - Knowledge Management (XMLForms) in SAP NetWeaver, versions 7.30, 7.31, 7.40 and 7.50 does not sufficiently validate an XML document accepted from an untrusted...
xml injectionakablindxpathcve
https://www.miggo.io/vulnerability-database/cve/CVE-2026-41674
CVE-2026-41674: xmldom Doctype XML Injection | Miggo
xmldom XML injection via createDocumentType injects arbitrary markup through unvalidated publicId, systemId, or internalSubset serialization, risking XXE.
xml injectioncvedoctype
https://api-security.blog/2022/05/30/microsoft-visual-studio-2008-express-ide-xml-injection/
Microsoft Visual Studio 2008 Express IDE XML Injection - API Security Blog
May 30, 2022 - Post ContentRead More
microsoft visual studioxml injectionapi securityexpresside
https://fluidattacks.com/pt/advisories/mono
xmltodict 0.14.2 - XML Injection | Fluid Attacks
CVE-2025-9375: XML injection vulnerability in xmltodict 0.14.2 allows attackers to inject malicious XML markup via crafted dictionary keys.
xml injectionfluidattacks
https://bugzilla.mozilla.org/show_bug.cgi?id=453915
453915 - (CVE-2008-5024) XML injection possible in E4X parsing via "default xml namespace"
VERIFIED (crowderbt) in Core - JavaScript Engine. Last updated 2009-01-14.
xml injectioncvepossibleparsingvia
https://redrays.io/blog/mdx-xml-injection-when-an-xmla-interface-is-used-sap-security-note-1530454/
MDX XML injection when an XMLA interface is used, SAP security note 1530454
Jan 10, 2012 - MDX XML injection when an XMLA interface is used, SAP security note 1530454
xml injectionsap securitymdxxmlainterface
https://threats.wiz.io/all-techniques/xml-injection
XML injection
xml injection
https://www.exploit-db.com/exploits/44430
KYOCERA Multi-Set Template Editor 3.4 - Out-Of-Band XML External Entity Injection - XML webapps...
Apr 9, 2018 - KYOCERA Multi-Set Template Editor 3.4 - Out-Of-Band XML External Entity Injection.. webapps exploit for XML platform
out of bandtemplate editorkyoceramultiset
https://www.medicines.org.uk/emc/product/15880/xpil/print
AMGEVITA HCF 40 mg solution for injection in pre-filled pen - XML Patient Information Leaflet...
AMGEVITA HCF 40 mg solution for injection in pre-filled pen - XML Patient Information Leaflet (XPIL) by Amgen Ltd - print friendly
patient information leafletamgevitahcfsolutioninjection
https://sec-consult.com/vulnerability-lab/advisory/xml-tag-injection-in-bscw-server/
XML Tag injection in BSCW Server - SEC Consult
The BSCW Groupware does not properly encode the user supplied input, before passing it to the third party framework ReportLab. This allows an user to injection...
xmltaginjectionserversec
https://www.openwall.com/lists/oss-security/2022/09/22/1
oss-security - CVE-2022-40705: Apache SOAP: XML External Entity Injection (XXE) allows...
oss securitycveapachesoapxml
https://www.jetbrains.com/help/rider/Language_Injection_Settings_dialog__XML_Tag_Injection.html
Language Injection Settings dialog: XML Tag Injection | JetBrains Rider Documentation
settings dialogjetbrains riderlanguageinjectionxml
https://pentest-tools.com/vulnerabilities-exploits/episerver-7-blind-xml-external-entity-injection_28347
Episerver 7 - Blind XML External Entity Injection (CVE-2017-17762) - Vulnerability & Exploit...
Remote attackers can read sensitive files from the server, leading to information disclosure.
episerverblindxmlexternalentity