📦 Smoothwall Express

by Smoothwall

🔍 What is Smoothwall Express?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2019-25394

HIGH CVSS 7.2 Feb 16, 2026

This stored XSS vulnerability in Smoothwall Express allows attackers to inject malicious JavaScript through modem.cgi POST parameters. When users access affected pages, the stored scripts execute in t...

CVE-2019-25379

HIGH CVSS 7.2 Feb 16, 2026

This stored and reflected XSS vulnerability in Smoothwall Express allows attackers to inject malicious JavaScript via the urlfilter.cgi endpoint. When exploited, it enables arbitrary script execution ...

CVE-2019-25387

MEDIUM CVSS 6.1 Feb 16, 2026

This reflected cross-site scripting vulnerability in Smoothwall Express allows unauthenticated attackers to inject malicious JavaScript via crafted POST requests to the xtaccess.cgi endpoint. When vic...

CVE-2019-25389

MEDIUM CVSS 6.1 Feb 16, 2026

This reflected cross-site scripting vulnerability in Smoothwall Express allows unauthenticated attackers to inject malicious JavaScript into users' browsers by manipulating the MACHINES parameter in r...

CVE-2019-25392

MEDIUM CVSS 6.1 Feb 16, 2026

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability in the iptools.cgi endpoint. Unauthenticated attackers can inject malicious JavaScript via the I...

CVE-2019-25381

MEDIUM CVSS 6.1 Feb 16, 2026

This vulnerability allows attackers to inject malicious JavaScript into Smoothwall Express web interface pages through unvalidated parameters in the hosts.cgi script. When users view the affected page...

CVE-2019-25385

MEDIUM CVSS 6.1 Feb 16, 2026

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability in the outgoing.cgi endpoint. Attackers can inject malicious JavaScript via MACHINE and MACHINEC...

CVE-2019-25383

MEDIUM CVSS 6.1 Feb 16, 2026

This CVE describes multiple reflected cross-site scripting (XSS) vulnerabilities in Smoothwall Express's apcupsd.cgi script. Attackers can inject malicious JavaScript through various POST parameters, ...

CVE-2019-25378

MEDIUM CVSS 6.1 Feb 16, 2026

This CVE describes multiple cross-site scripting vulnerabilities in Smoothwall Express 3.1's proxy.cgi endpoint. Attackers can inject malicious JavaScript through proxy configuration parameters, which...