AlgoSec develops network security policy and firewall management tools, with its footprint concentrated in products such as FireFlow and Firewall Analyzer that serve as control points for enterprise firewall configurations and change workflows. The vendor's vulnerabilities recur through application-layer weakness classes including cross-site scripting, path traversal, and improper privilege management, which are typical of web-facing administrative interfaces, and frequently acquire public exploit code. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by AlgoSec over time
Of all the CVEs published by AlgoSec as a CNA, 100.0% affect products that AlgoSec develops as a vendor.
Of all the CVEs published that affect products developed by AlgoSec, 50.0% are self-published by AlgoSec as a CNA.
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-12382HIGH Improper Limitation of a Pathname 'Path Traversal') vulnerability in Algosec Firewall Analyzer on Linux, 64 bit allows an authenticated user to upload files to a restricted directo | Nov 12, 2025 | 8.8 | 28 | NO | NO |
CVE-2013-5092MEDIUM Cross-site scripting (XSS) vulnerability in afa/php/Login.php in AlgoSec Firewall Analyzer 6.1-b86 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | Jan 29, 2014 | 4.3 | 26 | NO | YES |
CVE-2025-12381HIGH Improper Privilege Management vulnerability in AlgoSec Firewall Analyzer on Linux, 64 bit allows Privilege Escalation, Parameter Injection.
A local user with access to the command | Dec 9, 2025 | 7.8 | 24 | NO | NO |
CVE-2022-36783MEDIUM AlgoSec – FireFlow Reflected Cross-Site-Scripting (RXSS) A malicious user injects JavaScript code into a parameter called IntersectudRule on the search/result.html page. The malici | Oct 25, 2022 | 5.4 | 20 | NO | NO |
CVE-2023-46595MEDIUM Net-NTLM leak via HTML injection in FireFlow VisualFlow workflow editor allows an attacker to obtain victim’s domain credentials and Net-NTLM hash which can lead to relay domain at | Nov 2, 2023 | 5.4 | 18 | NO | NO |
CVE-2023-46596MEDIUM
Improper input validation in Algosec FireFlow VisualFlow workflow editor via Name, Description and Configuration File field in version A32.20, A32.50, A32.60 permits an attacker t | Feb 15, 2024 | 6.1 | 17 | NO | NO |
CVE-2013-7318MEDIUM Cross-site scripting (XSS) vulnerability in BusinessFlow/login in AlgoSec Firewall Analyzer 6.4 allows remote attackers to inject arbitrary web script or HTML via the message param | Jan 29, 2014 | 4.3 | 17 | NO | NO |
CVE-2014-4164MEDIUM Cross-site scripting (XSS) vulnerability in AlgoSec FireFlow 6.3-b230 allows remote attackers to inject arbitrary web script or HTML via a user signature to SelfService/Prefs.html. | Jun 16, 2014 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by AlgoSec.
Media articles that mention a CVE ID that affects a product developed by AlgoSec — matched by CVE ID, not by vendor name.