Forcepoint
Forcepoint WEB Security: vulnerabilities and CVEs
Forcepoint WEB Security has 7 published vulnerabilities, 1 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs7
Last 12 months1
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2274 | Medium (4.8) | 0.16% | — | Mar 16, 2026 | Improper Neutralization of Input During Web Page Generation in Forcepoint Web Security (On-Prem) on Windows allows Stored XSS.This issue affects Web Security through 8.5.6. |
| CVE-2023-6452 | Critical (9.6) | 0.42% | — | Aug 22, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Web Security (Transaction Viewer) allows Stored XSS. The Forcepoint Web Security portal allows… |
| CVE-2023-2080 | Critical (9.8) | 0.51% | — | Jun 15, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud allows Blind SQL… |
| CVE-2023-26292 | Medium (6.1) | 0.35% | — | Mar 29, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud… |
| CVE-2023-26291 | Medium (6.1) | 0.35% | — | Mar 29, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud (login_form.mhtml… |
| CVE-2023-26290 | Medium (6.1) | 0.35% | — | Mar 29, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud… |
| CVE-2019-6146 | Medium (6.1) | 3.0% | — | Jan 22, 2020 | It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection. CVSSv3.0: 5.3 (Medium) (/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) |
Other products by Forcepoint
Email Security · 9ONE Endpoint · 4Cloud Security Gateway · 4Next Generation Firewall · 3WEB Security Content Gateway · 2Data Loss Prevention · 2Next Generation Firewall Security Management Center · 2VPN Client · 2ONE Endpoint With Policy Engine · 1ONE Smartedge Agent · 1Security Engine · 1Security Manager · 1