Improper neutralization of special elements in the /IDC_Logging/checkifdone.cgi script in International Datacasting Corp
samlify is a Node.js library for SAML single sign-on. Prior to version 2.13.0, samlify’s template substitution only esca
authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2
Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's self-hosted SAML app
Wondershare FamiSafe 1.0 contains an unquoted service path vulnerability in the FSService that allows local users to pot
Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrar
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In xmldom
Kirby is an open-source content management system. Kirby's `Xml::value()` method has special handling for `<![CDATA[ ]]>
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, pam_usb builds XPath
fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Prior to version
fast-xml-builder builds XML from JSON. In 1.1.5, the fix for CVE-2026-41650 in fast-xml-parser sanitizes -- sequences in
fast-xml-builder builds XML from JSON. Prior to 1.1.7, when an input data has quotes in attribute values but process ent
Guzzle Services provides an implementation of the Guzzle Command library that uses Guzzle service descriptions to descri
Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the KML
A flaw was found in wildfly-core. A remote user authenticated as an administrative user can inject a malformed payload i
Astro is a web framework for content-driven websites. In versions 1.0.0 through 4.0.18, the source.title and enclosure.t
XML Injection (aka Blind XPath Injection) vulnerability in Drupal Central Authentication System (CAS) Server allows Priv
Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XM
XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, XML Injection. This vu
XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, XML Injection. This vu
Frequently Asked Questions
What is CWE-91?
CWE-91 (CWE-91) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-91?
There are 28 CVE records associated with CWE-91 in our database. Of these, 0 are critical severity, 11 are high severity, and 9 are medium severity.
How can I protect against CWE-91 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-91 using AI-powered security agents.
Detect CWE-91 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-91 vulnerabilities across your infrastructure.
Get Started