← לוח פגיעויות

CVE-2026-13376

בינונית 4.8

תיאור (מקור, אנגלית)

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS spamBlocker module allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-1071. This issue affects Fireware OS 12.0 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.

מדדים

CVSS 3.1
4.8 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CVSS 4.0
4.8 (MEDIUM) מקור הציון: CNA CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-15/8/2026
CWE
CWE-79

מוצרים מושפעים

watchguard: fireware; watchguard: firebox m270; watchguard: firebox m290; watchguard: firebox m370; watchguard: firebox m390; watchguard: firebox m440; watchguard: firebox m4600; watchguard: firebox m470; watchguard: firebox m4800; watchguard: firebox m5600; watchguard: firebox m570; watchguard: firebox m5800; watchguard: firebox m590; watchguard: firebox m670; watchguard: firebox m690

קישורים