云虫漏洞情报

CVE-2026-13376 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS spamBlocker module allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-1071. This issue affects Fireware OS 12.0 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2. - 漏洞详情

漏洞编号:CVE-2026-13376

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-13376

CNNVD 编号:-

厂商/产品:watchguard / fireware

影响范围:cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:*

CWE:CWE-79

发布/更新时间:2026-07-03 / 2026-08-28

漏洞描述

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS spamBlocker module allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-1071.

This issue affects Fireware OS 12.0 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.

相关链接

相关漏洞

« 返回首页