Forcepoint
Forcepoint WEB Security: vulnerabilidades y CVE
Forcepoint WEB Security tiene 7 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses1
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-2274 | Media (4.8) | 0.16% | — | 16 mar 2026 | Improper Neutralization of Input During Web Page Generation in Forcepoint Web Security (On-Prem) on Windows allows Stored XSS.This issue affects Web Security through 8.5.6. |
| CVE-2023-6452 | Crítica (9.6) | 0.42% | — | 22 ago 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Web Security (Transaction Viewer) allows Stored XSS. The Forcepoint Web Security portal allows… |
| CVE-2023-2080 | Crítica (9.8) | 0.51% | — | 15 jun 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud allows Blind SQL… |
| CVE-2023-26292 | Media (6.1) | 0.35% | — | 29 mar 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud… |
| CVE-2023-26291 | Media (6.1) | 0.35% | — | 29 mar 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud (login_form.mhtml… |
| CVE-2023-26290 | Media (6.1) | 0.35% | — | 29 mar 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud… |
| CVE-2019-6146 | Media (6.1) | 3.0% | — | 22 ene 2020 | It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection. CVSSv3.0: 5.3 (Medium) (/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) |
Otros productos de Forcepoint
Email Security · 9ONE Endpoint · 4Cloud Security Gateway · 4Next Generation Firewall · 3WEB Security Content Gateway · 2Data Loss Prevention · 2Next Generation Firewall Security Management Center · 2VPN Client · 2ONE Endpoint With Policy Engine · 1ONE Smartedge Agent · 1Security Engine · 1Security Manager · 1