Robuta

https://advisories.gitlab.com/pypi/reportlab/CVE-2019-17626/ XML Injection in ReportLab | GitLab Advisory Database (GLAD) CVE-2019-17626 XML Injection in ReportLab: ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by... xml injectionreportlabgitlabadvisorydatabase https://advisories.gitlab.com/npm/@xmldom/xmldom/CVE-2026-34601/ xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion |... CVE-2026-34601 xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion: @xmldom/xmldom allows attacker-controlled... xml injection https://advisories.gitlab.com/composer/getkirby/cms/CVE-2026-32870/ Kirby has XML injection in its XML creator toolkit | GitLab Advisory Database (GLAD) xml injection https://advisories.gitlab.com/npm/@xmldom/xmldom/CVE-2026-41674/ xmldom has XML injection through unvalidated DocumentType serialization | GitLab Advisory Database... CVE-2026-41674 xmldom has XML injection through unvalidated DocumentType serialization: The package serializes DocumentType node fields (internalSubset,... xml injection https://advisories.gitlab.com/composer/magento/project-community-edition/CVE-2021-36033/ Magento XML Injection vulnerability in the Widgets Module | GitLab Advisory Database (GLAD) CVE-2021-36033 Magento XML Injection vulnerability in the Widgets Module: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and... xml injection https://advisories.gitlab.com/npm/nodebb/CVE-2023-43187/ XML Injection (aka Blind XPath Injection) | GitLab Advisory Database (GLAD) CVE-2023-43187 XML Injection (aka Blind XPath Injection): A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum... xml injectionakablindxpathgitlab https://advisories.gitlab.com/composer/magento/community-edition/CVE-2023-29289/ Magento Open Source allows XML Injection | GitLab Advisory Database (GLAD) CVE-2023-29289 Magento Open Source allows XML Injection: Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are... magento open sourcexml injectionallowsgitlabadvisory https://advisories.gitlab.com/composer/magento/community-edition/CVE-2023-22247/ Magento Open Source allows XML Injection | GitLab Advisory Database (GLAD) CVE-2023-22247 Magento Open Source allows XML Injection: Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an XML... magento open sourcexml injectionallowsgitlabadvisory https://advisories.gitlab.com/pypi/geonode/CVE-2023-26043/ GeoServer style upload functionality vulnerable to XML External Entity (XXE) injection | GitLab... CVE-2023-26043 GeoServer style upload functionality vulnerable to XML External Entity (XXE) injection: GeoNode is vulnerable to an XML External Entity (XXE)... https://advisories.gitlab.com/npm/fast-xml-parser/CVE-2026-25896/ fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names | GitLab... CVE-2026-25896 fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names: A dot (.) in a DOCTYPE entity name is treated as a... https://advisories.gitlab.com/npm/@xmldom/xmldom/CVE-2026-41672/ xmldom has XML node injection through unvalidated comment serialization | GitLab Advisory Database... CVE-2026-41672 xmldom has XML node injection through unvalidated comment serialization: The package allows attacker-controlled comment content to be serialized... https://advisories.gitlab.com/maven/org.dspace/dspace-api/CVE-2025-53621/ DSpace is vulnerable to XML External Entity injection during archive imports | GitLab Advisory... CVE-2025-53621 DSpace is vulnerable to XML External Entity injection during archive imports : Two related XXE injection possibilities have been discovered,... xml external entity injection https://www.drupal.org/sa-contrib-2026-007 Central Authentication System (CAS) Server - Less critical - XML Element Injection -... Jan 28, 2026 - This module enables you to turn a Drupal install into the Central Authentication System (CAS). It makes your database the primary location for other systems to... centralauthenticationsystemcasserver https://advisories.gitlab.com/composer/magento/community-edition/CVE-2021-36022/ Magento XML Injection vulnerability in the Widgets Update Layout | GitLab Advisory Database (GLAD) CVE-2021-36022 Magento XML Injection vulnerability in the Widgets Update Layout: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and... https://securitylab.github.com/advisories/GHSL-2022-131_OWSLib/ GHSL-2022-131: XML External Entities (XXE) injection in OWSLib - CVE-2023-27476 | GitHub Security... Mar 15, 2023 - OWSLib does not disable entity resolution for XML parsing, leading to XML External Entities (XXE) injection. https://advisories.gitlab.com/npm/@dicebear/converter/CVE-2026-33418/ SVG Dimension Capping Bypass via XML Comment Injection in @dicebear/converter ensureSize() | GitLab... CVE-2026-33418 SVG Dimension Capping Bypass via XML Comment Injection in @dicebear/converter ensureSize(): The ensureSize() function in @dicebear/converter... https://advisories.gitlab.com/npm/@xmldom/xmldom/CVE-2026-41675/ xmldom has XML node injection through unvalidated processing instruction serialization | GitLab... CVE-2026-41675 xmldom has XML node injection through unvalidated processing instruction serialization: The package allows attacker-controlled processing... xmlnodeinjection https://bugzilla.mozilla.org/show_bug.cgi?id=453915 453915 - (CVE-2008-5024) XML injection possible in E4X parsing via "default xml namespace" VERIFIED (crowderbt) in Core - JavaScript Engine. Last updated 2009-01-14. https://advisories.gitlab.com/maven/org.verapdf/verapdf-library/CVE-2024-52800/ veraPDF CLI has potential XXE (XML External Entity Injection) vulnerability | GitLab Advisory... CVE-2024-52800 veraPDF CLI has potential XXE (XML External Entity Injection) vulnerability: Executing policy checks using custom schematron files via the CLI... xml external entity injection https://advisories.gitlab.com/maven/org.jvnet.hudson.main/hudson-core/CVE-2015-8031/ Hudson XML API susceptible to External Entity Injection Vunerability prior to v3.3.2 | GitLab... CVE-2015-8031 Hudson XML API susceptible to External Entity Injection Vunerability prior to v3.3.2: Hudson (aka org.jvnet.hudson.main:hudson-core) before 3.3.2... https://applicationsecurityauthority.com/xml-security-vulnerabilities/ XML Security Vulnerabilities (XXE, XPath Injection) XML-based attack vectors represent a persistent class of application-layer vulnerabilities that target the parsing and querying of structured data. This page... security vulnerabilitiesxmlxxexpathinjection https://advisories.gitlab.com/pypi/fonttools/CVE-2025-66034/ fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib | GitLab... CVE-2025-66034 fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib: The fonttools varLib (or python3 -m fontTools.varLib)... https://advisories.gitlab.com/npm/fast-xml-parser/CVE-2023-34104/ fast-xml-parser vulnerable to Regex Injection via Doctype Entities | GitLab Advisory Database (GLAD) CVE-2023-34104 fast-xml-parser vulnerable to Regex Injection via Doctype Entities: "fast-xml-parser" allows special characters in entity names, which are not... https://advisories.gitlab.com/maven/io.github.robothy/local-s3-rest/GHSA-v232-254c-m6p7/ LocalS3 Project Vulnerable to XML External Entity (XXE) Injection via Bucket Tagging API | GitLab... GHSA-v232-254c-m6p7 LocalS3 Project Vulnerable to XML External Entity (XXE) Injection via Bucket Tagging API: The LocalS3 project, an S3-compatible storage... https://www.jetbrains.com/help/objc/language-injection-settings-dialog-xml-attribute-injection.html Language Injection Settings dialog: XML Attribute Injection | AppCode Documentation languageinjectionsettingsdialogxml https://www.jetbrains.com/help/webstorm/language-injection-settings-dialog-xml-tag-injection.html Language Injection Settings dialog: XML Tag Injection | WebStorm Documentation languageinjectionsettingsdialogxml https://www.jetbrains.com/help/phpstorm/language-injection-settings-dialog-xml-attribute-injection.html Language Injection Settings dialog: XML Attribute Injection | PhpStorm Documentation languageinjectionsettingsdialogxml https://advisories.gitlab.com/composer/magento/community-edition/CVE-2021-36023/ Magento XML Injection vulnerability in the Widgets Update Layout | GitLab Advisory Database (GLAD) CVE-2021-36023 Magento XML Injection vulnerability in the Widgets Update Layout: Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and...