CVE-2025-1071
A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the spamBlocker mo
CVSS
4.8
Medium
EPSS
0.3%
p22
KEV
—
Exploit Today
7
0-100
Published: Feb 14, 2025 · Last modified: Aug 8, 2026 · CWE-79
0.3%EPSS · 30 days0.3%
2026-08-102026-09-07
A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the spamBlocker module. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-818244.7 MED—
———The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered to click on a malicious link.3hCVE-2026-696904.6 MED—
———Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.3hCVE-2026-696153.5 LOW—
———Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.3hCVE-2026-694177.3 HIG—
———Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.3hCVE-2026-694027.3 HIG—
———Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.3hCVE-2026-693569.3 CRI—
———Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.3h