Smoothwall
Smoothwall Express: vulnerabilities and CVEs
Smoothwall Express has 21 published vulnerabilities, 19 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs21
Last 12 months19
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27508 | Medium (5.1) | 0.27% | — | Mar 30, 2026 | Smoothwall Express versions prior to 3.1 Update 13 contain a reflected cross-site scripting vulnerability in the /redirect.cgi endpoint due to improper sanitation of the url parameter. Attackers can craft malicious URLs… |
| CVE-2026-26352 | Medium (5.1) | 0.24% | — | Mar 30, 2026 | Smoothwall Express versions prior to 3.1 Update 13 contain a stored cross-site scripting vulnerability in the /cgi-bin/vpnmain.cgi script due to improper sanitation of the VPN_IP parameter. Authenticated attackers can… |
| CVE-2019-25395 | Medium (5.3) | 0.23% | — | Feb 16, 2026 | Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple stored cross-site scripting vulnerabilities in the preferences.cgi script that allow attackers to inject malicious scripts through the HOSTNAME, KEYMAP,… |
| CVE-2019-25394 | Medium (5.3) | 0.23% | — | Feb 16, 2026 | Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple stored cross-site scripting vulnerabilities in the modem.cgi script that allow attackers to inject malicious scripts through POST parameters. Attackers… |
| CVE-2019-25393 | Medium (5.1) | 0.24% | — | Feb 16, 2026 | Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting insufficient input validation.… |
| CVE-2019-25392 | Medium (5.1) | 0.25% | — | Feb 16, 2026 | Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the IP parameter. Attackers can… |
| CVE-2019-25390 | Medium (4.8) | 0.21% | — | Feb 16, 2026 | Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the interfaces.cgi script that allow attackers to inject malicious scripts through multiple parameters… |
| CVE-2019-25389 | Medium (5.1) | 0.25% | — | Feb 16, 2026 | Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the MACHINES parameter. Attackers… |
| CVE-2019-25388 | Medium (5.1) | 0.25% | — | Feb 16, 2026 | Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted input to the ipblock.cgi… |
| CVE-2019-25387 | Medium (5.1) | 0.25% | — | Feb 16, 2026 | Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted input to the xtaccess.cgi… |
| CVE-2019-25386 | Medium (5.1) | 0.23% | — | Feb 16, 2026 | Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the dmzholes.cgi script that allow attackers to inject malicious scripts through unvalidated… |
| CVE-2019-25385 | Medium (5.1) | 0.23% | — | Feb 16, 2026 | Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the MACHINE and MACHINECOMMENT parameters.… |
| CVE-2019-25384 | Medium (5.1) | 0.23% | — | Feb 16, 2026 | Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the portfw.cgi script that allow attackers to inject malicious scripts through unvalidated parameters.… |
| CVE-2019-25383 | Medium (5.1) | 0.23% | — | Feb 16, 2026 | Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the apcupsd.cgi script that allow attackers to inject malicious scripts through multiple POST… |
| CVE-2019-25382 | Medium (5.1) | 0.26% | — | Feb 16, 2026 | Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the NTP_SERVER parameter.… |
| CVE-2019-25381 | Medium (5.1) | 0.23% | — | Feb 16, 2026 | Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the hosts.cgi script that allow attackers to inject malicious scripts through unvalidated parameters.… |
| CVE-2019-25380 | Medium (5.1) | 0.23% | — | Feb 16, 2026 | Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the dhcp.cgi script that allow attackers to inject malicious scripts through multiple parameters.… |
| CVE-2019-25379 | Medium (5.3) | 0.26% | — | Feb 16, 2026 | Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains stored and reflected cross-site scripting vulnerabilities in the urlfilter.cgi endpoint that allow attackers to inject malicious scripts. Attackers can submit… |
| CVE-2019-25378 | Medium (5.1) | 0.23% | — | Feb 16, 2026 | Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple cross-site scripting vulnerabilities in the proxy.cgi endpoint that allow attackers to inject malicious scripts through parameters including CACHE_SIZE,… |
| CVE-2011-1085 | High (8.8) | 0.46% | — | Feb 7, 2020 | CSRF vulnerability in Smoothwall Express 3. |
| CVE-2011-1084 | Medium (6.1) | 0.65% | — | Feb 7, 2020 | A cross-site scripting (XSS) vulnerability in Smoothwall Express 3. |