目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-91 XML注入(XPath盲注) 类漏洞列表 72

CWE-91 XML注入(XPath盲注) 类弱点 72 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-91即XML注入(又称盲XPath注入),属于输入验证缺陷。攻击者通过注入恶意XML字符或结构,篡改XML语法与内容,从而绕过逻辑控制或执行非预期命令。开发者应严格对用户输入进行白名单验证,对特殊字符如<、>、&等进行实体编码或转义,并使用安全的XML解析库,避免直接拼接用户数据,以阻断注入路径。

MITRE CWE 官方描述
CWE:CWE-91 XML Injection(又称 Blind XPath Injection) 英文:产品未能正确中和 XML 中使用的特殊元素,导致攻击者可以在 XML 被最终系统处理之前修改其语法、内容或命令。 在 XML 中,特殊元素可能包括保留字或字符,如 "<"、">"、""" 和 "&",这些元素可用于添加新数据或修改 XML 语法。
常见影响 (1)
Confidentiality, Integrity, Availability Execute Unauthorized Code or Commands, Read Application Data, Modify Application Data
缓解措施 (1)
Implementation Assume all input is malicious. Use an "accept known good" input validation strategy, i.e., use a list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does. When performing input validation, consider all potentially relevant properties, including length, type of input, the full range…
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-1554 Drupal Central Authentication System Server 安全漏洞 — Central Authentication System (CAS) Server 8.8AI High AI 2026-02-04
CVE-2022-50902 Wondershare FamiSafe 安全漏洞 — Wondershare FamiSafe 8.4 High 2026-01-13
CVE-2025-1545 WatchGuard Fireware OS 安全漏洞 — Fireware OS 8.2 High 2025-12-04
CVE-2025-66034 FontTools 安全漏洞 — fonttools 6.3 Medium 2025-11-29
CVE-2025-12921 OpenClinica Community Edition 安全漏洞 — Community Edition 4.3 Medium 2025-11-09
CVE-2025-7473 ZOHO ManageEngine Endpoint Central 安全漏洞 — Endpoint Central 5.2 Medium 2025-10-21
CVE-2025-54251 Adobe Experience Manager 安全漏洞 — Adobe Experience Manager 4.3 Medium 2025-09-09
CVE-2025-24404 Apache HertzBeat 安全漏洞 — Apache HertzBeat (incubating) 8.8AI High AI 2025-09-09
CVE-2025-9375 xmltodict 安全漏洞 — xmltodict 9.1AI Critical AI 2025-09-01
CVE-2025-49538 Adobe ColdFusion 安全漏洞 — ColdFusion 7.4 High 2025-07-08
CVE-2024-47113 IBM ICP Voice Gateway 安全漏洞 — Voice Gateway 8.1 High 2025-01-18
CVE-2024-13190 myblog 安全漏洞 — myblog 6.3 Medium 2025-01-08
CVE-2024-53675 Hewlett Packard Enterprise Insight Remote Support 安全漏洞 — HPE Insight Remote Support 7.3 High 2024-11-26
CVE-2024-53674 Hewlett Packard Enterprise Insight Remote Support 安全漏洞 — HPE Insight Remote Support 7.3 High 2024-11-26
CVE-2024-11622 Hewlett Packard Enterprise Insight Remote Support 安全漏洞 — HPE Insight Remote Support 7.3 High 2024-11-26
CVE-2024-42374 SAP BEx Web Java Runtime Export Web Service 安全漏洞 — SAP BEx Web Java Runtime Export Web Service 8.2 High 2024-08-13
CVE-2023-32173 Unified Automation UaGateway 安全漏洞 — UaGateway 6.5 - 2024-05-03
CVE-2023-27328 Corel Parallels Desktop 安全漏洞 — Desktop 8.8 - 2024-05-03
CVE-2024-28109 veraPDF-library 安全漏洞 — veraPDF-library 8.1 High 2024-03-28
CVE-2023-46214 Splunk 安全漏洞 — Splunk Enterprise 8.0 High 2023-11-16
CVE-2022-32755 IBM Security Directory Server 代码问题漏洞 — Security Directory Server 5.5 Medium 2023-10-14
CVE-2022-4245 codehaus-plexus 代码问题漏洞 — RHINT Camel-K-1.10.1 4.3 Medium 2023-09-25
CVE-2023-40612 OpenNMS Horizon 安全漏洞 — Horizon 5.3 Medium 2023-08-23
CVE-2023-38207 Adobe Commerce 安全漏洞 — Adobe Commerce 7.5 High 2023-08-09
CVE-2023-29289 Adobe Commerce 安全漏洞 — Magento Commerce 6.5 Medium 2023-06-15
CVE-2023-22247 Adobe Commerce 安全漏洞 — Magento Commerce 7.5 High 2023-03-27
CVE-2022-35259 Ivanti Endpoint Manager 安全漏洞 — Ivanti Endpoint Manager 7.8 - 2022-12-05
CVE-2022-22244 Juniper Networks Junos OS 安全漏洞 — Junos OS 5.3 Medium 2022-10-18
CVE-2022-34253 Adobe Magento Open Source 安全漏洞 — Magento Commerce 7.2 - 2022-08-16
CVE-2022-2458 Business-central 代码问题漏洞 — Red Hat Process Automation Manager 7 8.2 - 2022-08-09

CWE-91(XML注入(XPath盲注)) 是常见的弱点类别,本平台收录该类弱点关联的 72 条 CVE 漏洞。