CWE-91 XML注入(XPath盲注) 类弱点 53 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-91即XML注入(又称盲XPath注入),属于输入验证缺陷。攻击者通过注入恶意XML字符或结构,篡改XML语法与内容,从而绕过逻辑控制或执行非预期命令。开发者应严格对用户输入进行白名单验证,对特殊字符如<、>、&等进行实体编码或转义,并使用安全的XML解析库,避免直接拼接用户数据,以阻断注入路径。
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-47273 | pam_usb 安全漏洞 — pam_usb | 6.5 | Medium | 2026-05-27 |
| CVE-2026-44664 | fast-xml-parser 安全漏洞 — fast-xml-builder | 6.1 | Medium | 2026-05-13 |
| CVE-2026-44665 | fast-xml-builder 安全漏洞 — fast-xml-builder | 6.1 | Medium | 2026-05-13 |
| CVE-2026-41650 | fast-xml-parser 安全漏洞 — fast-xml-parser | 6.1 | Medium | 2026-05-07 |
| CVE-2026-41675 | XMLDOM 安全漏洞 — xmldom | 10.0AI | CriticalAI | 2026-05-07 |
| CVE-2026-41674 | XMLDOM 安全漏洞 — xmldom | 7.5AI | HighAI | 2026-05-07 |
| CVE-2026-41672 | XMLDOM 安全漏洞 — xmldom | 10.0AI | CriticalAI | 2026-05-07 |
| CVE-2026-27693 | Traccar 安全漏洞 — traccar | 5.4 | Medium | 2026-05-05 |
| CVE-2026-32870 | Kirby 安全漏洞 — kirby | 7.1AI | HighAI | 2026-04-24 |
| CVE-2026-34601 | XMLDOM 安全漏洞 — xmldom | 7.5 | High | 2026-04-02 |
| CVE-2026-28770 | International Datacasting SFX Series SuperFlex Satellite Receiver Web management interface 安全漏洞 — SFX Series SuperFlex Satellite Receiver Web management interface | 5.4AI | MediumAI | 2026-03-04 |
| CVE-2026-1554 | Drupal Central Authentication System Server 安全漏洞 — Central Authentication System (CAS) Server | 8.8AI | HighAI | 2026-02-04 |
| CVE-2022-50902 | Wondershare FamiSafe 安全漏洞 — Wondershare FamiSafe | 8.4 | High | 2026-01-13 |
| CVE-2025-1545 | WatchGuard Fireware OS 安全漏洞 — Fireware OS | 7.5AI | HighAI | 2025-12-04 |
| CVE-2025-66034 | FontTools 安全漏洞 — fonttools | 6.3 | Medium | 2025-11-29 |
| CVE-2025-12921 | OpenClinica Community Edition 安全漏洞 — Community Edition | 4.3 | Medium | 2025-11-09 |
| CVE-2025-7473 | ZOHO ManageEngine Endpoint Central 安全漏洞 — Endpoint Central | 5.2 | Medium | 2025-10-21 |
| CVE-2025-54251 | Adobe Experience Manager 安全漏洞 — Adobe Experience Manager | 4.3 | Medium | 2025-09-09 |
| CVE-2025-24404 | Apache HertzBeat 安全漏洞 — Apache HertzBeat (incubating) | 8.8AI | HighAI | 2025-09-09 |
| CVE-2025-9375 | xmltodict 安全漏洞 — xmltodict | 9.1AI | CriticalAI | 2025-09-01 |
| CVE-2025-49538 | Adobe ColdFusion 安全漏洞 — ColdFusion | 7.4 | High | 2025-07-08 |
| CVE-2024-47113 | IBM ICP Voice Gateway 安全漏洞 — Voice Gateway | 8.1 | High | 2025-01-18 |
| CVE-2024-13190 | myblog 安全漏洞 — myblog | 6.3 | Medium | 2025-01-08 |
| CVE-2024-53675 | Hewlett Packard Enterprise Insight Remote Support 安全漏洞 — HPE Insight Remote Support | 7.3 | High | 2024-11-26 |
| CVE-2024-53674 | Hewlett Packard Enterprise Insight Remote Support 安全漏洞 — HPE Insight Remote Support | 7.3 | High | 2024-11-26 |
| CVE-2024-11622 | Hewlett Packard Enterprise Insight Remote Support 安全漏洞 — HPE Insight Remote Support | 7.3 | High | 2024-11-26 |
| CVE-2024-42374 | SAP BEx Web Java Runtime Export Web Service 安全漏洞 — SAP BEx Web Java Runtime Export Web Service | 8.2 | High | 2024-08-13 |
| CVE-2023-32173 | Unified Automation UaGateway 安全漏洞 — UaGateway | 6.5 | - | 2024-05-03 |
| CVE-2023-27328 | Corel Parallels Desktop 安全漏洞 — Desktop | 8.8 | - | 2024-05-03 |
| CVE-2024-28109 | veraPDF-library 安全漏洞 — veraPDF-library | 8.1 | High | 2024-03-28 |
CWE-91(XML注入(XPath盲注)) 是常见的弱点类别,本平台收录该类弱点关联的 53 条 CVE 漏洞。