📦 Ipfire

by Ipfire

🔍 What is Ipfire?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-34311

HIGH CVSS 8.8 Oct 28, 2025

This CVE describes a command injection vulnerability in IPFire firewall software that allows authenticated attackers to execute arbitrary commands as the 'nobody' user when creating proxy reports. The...

CVE-2021-33393

HIGH CVSS 8.8 Jun 9, 2021

This vulnerability in IPFire firewall distributions allows local privilege escalation through insecure file permissions. An unprivileged user could replace the backup.pl script with malicious code tha...

CVE-2019-25398

MEDIUM CVSS 6.1 Feb 18, 2026

This CVE describes multiple cross-site scripting vulnerabilities in IPFire's ovpnmain.cgi script that allow attackers to inject malicious JavaScript through VPN configuration parameters. When exploite...

CVE-2019-25400

MEDIUM CVSS 5.4 Feb 18, 2026

This vulnerability allows attackers to execute reflected cross-site scripting (XSS) attacks against IPFire firewall administrators. By injecting malicious JavaScript into multiple parameters of the fw...

CVE-2019-25396

MEDIUM CVSS 6.1 Feb 18, 2026

CVE-2019-25396 is a reflected cross-site scripting (XSS) vulnerability in IPFire's updatexlrator.cgi script that allows attackers to inject malicious JavaScript via POST parameters. When exploited, at...

CVE-2025-34317

MEDIUM CVSS 5.4 Oct 28, 2025

This stored XSS vulnerability in IPFire allows authenticated attackers to inject malicious JavaScript through DNS configuration settings. When other users view the compromised DNS entries, the injecte...

CVE-2025-34308

MEDIUM CVSS 5.4 Oct 28, 2025

This stored XSS vulnerability in IPFire allows authenticated attackers to inject malicious JavaScript into the time synchronization settings page. When other users view the affected configuration page...

CVE-2025-34309

MEDIUM CVSS 5.4 Oct 28, 2025

This stored XSS vulnerability in IPFire allows authenticated attackers to inject malicious JavaScript into Dynamic DNS host configurations. When other users view or edit these compromised entries, the...

CVE-2025-34310

MEDIUM CVSS 5.4 Oct 28, 2025

This stored XSS vulnerability in IPFire allows authenticated attackers to inject malicious JavaScript into Quality of Service settings. When other users view the compromised QoS entries, the scripts e...

CVE-2025-34313

MEDIUM CVSS 5.4 Oct 28, 2025

This stored XSS vulnerability in IPFire allows authenticated attackers to inject malicious JavaScript through user quota rules. The injected code executes when other users view the affected quota entr...

CVE-2025-34314

MEDIUM CVSS 5.4 Oct 28, 2025

This stored XSS vulnerability in IPFire allows authenticated attackers to inject malicious JavaScript into time constraint rules. When other users view these rules in the web interface, the scripts ex...

CVE-2025-34315

MEDIUM CVSS 5.4 Oct 28, 2025

This stored XSS vulnerability in IPFire allows authenticated attackers to inject malicious JavaScript through the remote syslog configuration. When other users view the affected configuration page, th...

CVE-2025-34316

MEDIUM CVSS 5.4 Oct 28, 2025

This stored XSS vulnerability in IPFire allows authenticated attackers to inject malicious JavaScript through mail server configuration fields. When other users view the mail settings page, the inject...

CVE-2025-34301

MEDIUM CVSS 5.4 Oct 28, 2025

This stored XSS vulnerability in IPFire allows authenticated attackers to inject malicious JavaScript into location group configurations. When other users view the affected page, the script executes i...

CVE-2025-34302

MEDIUM CVSS 5.4 Oct 28, 2025

This stored XSS vulnerability in IPFire allows authenticated attackers to inject malicious JavaScript through service creation. When other users view the compromised service entry, the script executes...

CVE-2025-34303

MEDIUM CVSS 5.4 Oct 28, 2025

This stored XSS vulnerability in IPFire allows authenticated attackers to inject malicious JavaScript through whitelist host remarks. The injected code executes when other users view the compromised w...

CVE-2025-34304

MEDIUM CVSS 6.5 Oct 28, 2025

This SQL injection vulnerability in IPFire allows authenticated attackers to manipulate SQL queries when viewing OpenVPN connection logs. Attackers can exploit this to extract sensitive information fr...

CVE-2025-34305

MEDIUM CVSS 5.4 Oct 28, 2025

IPFire versions before 2.29 Core Update 198 contain stored XSS vulnerabilities where authenticated users can inject malicious scripts into various web interface fields. These scripts execute when othe...

CVE-2025-34306

MEDIUM CVSS 5.4 Oct 28, 2025

This stored XSS vulnerability in IPFire allows authenticated attackers to inject malicious JavaScript through the pienumber parameter when updating firewall IP search defaults. The injected code execu...

CVE-2025-34307

MEDIUM CVSS 5.4 Oct 28, 2025

This stored XSS vulnerability in IPFire allows authenticated attackers to inject malicious JavaScript through the firewall country search settings. The injected code executes when other users view tho...