CWE-917— Improper Neutralization of Special Elements Used in an Expression Language Statement (EL Injection)
187 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-917page 4 of 4
- CVE-2022-26134CRITICALCVSS 9.8EG 9.8⚠ KEV2022-06-03
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions …
- CVE-2022-34466MEDIUMCVSS 6.5EG 6.52022-07-12
A vulnerability has been identified in Mendix Applications using Mendix 9 (All versions >= V9.11 < V9.15), Mendix Applications using Mendix 9 (V9.12) (All versions < V9.12.3). An expression injection vulnerability was discovered in the Wor…
- CVE-2022-4146HIGHCVSS 7.3EG 7.32023-07-18
Expression Language Injection vulnerability in Hitachi Replication Manager on Windows, Linux, Solaris allows Code Injection.This issue affects Hitachi Replication Manager: before 8.8.5-02.
- CVE-2022-42009HIGHCVSS 8.0EG 8.02023-07-12
SpringEL injection in the server agent in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely. Users are recommended to upgrade to 2.7.7.
- CVE-2022-45855HIGHCVSS 8.0EG 8.02023-07-12
SpringEL injection in the metrics source in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely. Users are recommended to upgrade to 2.7.7.
- CVE-2023-20863MEDIUMCVSS 6.5EG 6.52023-04-13
In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
- CVE-2023-22665MEDIUMCVSS 5.4EG 5.42023-04-25
There is insufficient checking of user queries in Apache Jena versions 4.7.0 and earlier, when invoking custom scripts. It allows a remote user to execute arbitrary javascript via a SPARQL query.
- CVE-2023-26092CRITICALCVSS 9.8EG 9.82023-02-20
Liima before 1.17.28 allows server-side template injection.
- CVE-2023-27821CRITICALCVSS 9.8EG 9.82023-03-28
Databasir v1.0.7 was discovered to contain a remote code execution (RCE) vulnerability via the mockDataScript parameter.
- CVE-2023-32200HIGHCVSS 8.8EG 8.82023-07-12
There is insufficient restrictions of called script functions in Apache Jena versions 4.8.0 and earlier. It allows a remote user to execute javascript via a SPARQL query. This issue affects Apache Jena: from 3.7.0 through 4.8.0.
- CVE-2023-41331CRITICALCVSS 9.8EG 9.82023-09-12
SOFARPC is a Java RPC framework. Versions prior to 5.11.0 are vulnerable to remote command execution. Through a carefully crafted payload, an attacker can achieve JNDI injection or system command execution. In the default configuration of …
- CVE-2023-42658HIGHCVSS 8.8EG 8.82023-10-31
Archive command in Chef InSpec prior to 4.56.58 and 5.22.29 allow local command execution via maliciously crafted profile.
- CVE-2023-51593CRITICALCVSS 9.8EG 9.82024-05-03
Voltronic Power ViewPower Pro Expression Language Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Voltronic Power ViewPower Pro. Authenticatio…
- CVE-2024-0715HIGHCVSS 7.6EG 7.62024-02-20
Expression Language Injection vulnerability in Hitachi Global Link Manager on Windows allows Code Injection.This issue affects Hitachi Global Link Manager: before 8.8.7-03.
- CVE-2024-12798MEDIUMCVSS 5.9EG 0.02024-12-19
ACE vulnerability in JaninoEventEvaluator by QOS.CH logback-core upto including version 0.1 to 1.3.14 and 1.4.0 to 1.5.12 in Java applications allows attacker to execute arbitrary code by compromising an existing logbac…
- CVE-2024-4286MEDIUMCVSS 4.9EG 4.92024-05-26
Mintplex-Labs' anything-llm application is vulnerable to improper neutralization of special elements used in an expression language statement, identified in the commit id `57984fa85c31988b2eff429adfc654c46e0c342a`. The vulnerability arises…
- CVE-2024-51466CRITICALCVSS 9.0EG 9.02024-12-20
IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 is vulnerable to an Expression Language (EL) Injection vulnerability. A remote attacker could exploit this vulnerability to expose sensitive information, consume m…
- CVE-2024-5828HIGHCVSS 8.6EG 8.62024-08-06
Expression Language Injection vulnerability in Hitachi Tuning Manager on Windows, Linux, Solaris allows Code Injection.This issue affects Hitachi Tuning Manager: before 8.8.7-00.
- CVE-2024-7552MEDIUMCVSS 6.3EG 6.32024-08-06
A vulnerability was found in DataGear up to 5.0.0. It has been declared as critical. Affected by this vulnerability is the function evaluateVariableExpression of the file ConversionSqlParamValueMapper.java of the component Data Schema Page…
- CVE-2024-9672MEDIUMCVSS 5.4EG 5.42024-12-10
A reflected cross-site scripting (XSS) vulnerability exists in PaperCut NG/MF. This issue can be used to execute specially created JavaScript payloads in the browser. A user must click on a malicious link for this issue to occur.
- CVE-2025-11175HIGHCVSS 8.8EG 0.02026-01-30
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') vulnerability in The Wikimedia Foundation Mediawiki - DiscussionTools Extension allows Regular Expression Exponential Bl…
- CVE-2025-3322CRITICALCVSS 10.0EG 0.02025-06-06
An improper neutralization of inputs used in expression language allows remote code execution with the highest privileges on the server.
- CVE-2025-41243CRITICALCVSS 10.0EG 10.02025-09-16
Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification. An application should be considered vulnerable when all the following are true: * The application is using Spring Cloud Gateway Server …
- CVE-2025-41253HIGHCVSS 7.5EG 7.52025-10-16
The following versions of Spring Cloud Gateway Server Webflux may be vulnerable to the ability to expose environment variables and system properties to attackers. An application should be considered vulnerable when all the following are t…
- CVE-2026-2586CRITICALCVSS 9.1EG 9.12026-05-19
An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with…
- CVE-2026-2587CRITICALCVSS 9.6EG 9.62026-05-19
A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler. The application processes .xml files and evaluates user-supplied values within a cont…
- CVE-2026-26462HIGHCVSS 7.3EG 7.32026-05-18
Offline Hospital Management System 5.3.0 allows remote code execution due to an improper Electron renderer configuration. The application enables Node.js integration while disabling context isolation, allowing JavaScript executed in the re…
- CVE-2026-28201HIGHCVSS 7.8EG 7.82026-05-07
An improper input validation, together with an overly permissive default CORS configuration in Open Notebook v1.8.1 allows remote attacker to trick a legitimate user to alter or delete arbitrary database entries via specially crafted malic…
- CVE-2026-31380MEDIUMCVSS 6.5EG 6.52026-05-19
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to v…
- CVE-2026-39842CRITICALCVSS 9.9EG 9.92026-04-15
OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulnerabilities in the rules engine that allow arbitrary code execution on the server. The JavaScript rules engine executes …
- CVE-2026-40477CRITICALCVSS 9.0EG 9.02026-04-17
Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. Although the library provides mechanisms …
- CVE-2026-40478CRITICALCVSS 9.0EG 9.02026-04-17
Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanisms. Although the library provides mechani…
- CVE-2026-41705HIGHCVSS 8.6EG 8.62026-05-09
Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs. Spring AI 1.0.x: affected from 1.0.0 through latest 1.0.x; upgrade to 1.0.7 or greater. Spring AI 1.1.x:…
- CVE-2026-41883HIGHCVSS 8.1EG 8.12026-05-08
OmniFaces is a utility library for Faces. Prior to versions 1.14.2, 2.7.32, 3.14.16, 4.7.5, and 5.2.3, there is a server-side EL injection leading to Remote Code Execution (RCE). This affects applications that use CDNResourceHandler with a…
- CVE-2026-41901CRITICALCVSS 9.0EG 9.02026-05-12
Thymeleaf is a server-side Java template engine for web and standalone environments. Prior to 3.1.5.RELEASE, a security bypass vulnerability exists in the expression execution mechanisms of Thymeleaf. Although the library provides mechanis…
- CVE-2026-42811CRITICALCVSS 9.9EG 9.92026-05-04
In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or table name can cause those credentials to work across the configured bucket instead. Apache …
- CVE-2026-8759HIGHCVSS 7.3EG 7.32026-05-17
A vulnerability was identified in xiandafu beetl up to 3.20.2. Affected is an unknown function of the file beetl-classic-integration/beetl-spring-classic/src/main/java/org/beetl/ext/spring/SpELFunction.java of the component SpELFunction. T…
Map vulnerabilities like CWE-917 to your infrastructure
EchelonGraph correlates every CVE — across CWE-917 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →