Smoothwall develops a suite of network security and content-filtering appliances—including Smoothwall Express, NetworkGuardian, SchoolGuardian, and SmoothGuardian—that are deployed for gateway filtering and access control in schools and enterprise environments. Its vulnerability profile, while modest in overall volume, centers on a narrow but strategically positioned product line and recurs through web-facing input-handling flaws, particularly cross-site scripting and cross-site request forgery vulnerabilities in the management and filtering interfaces. Public exploit code has an elevated tendency to be available for vulnerabilities affecting this vendor, reflecting the appeal of these appliances as targets for gaining administrative access or bypassing content controls. The exposure pattern is characteristic of embedded security appliances where management interfaces and filtering logic are frequent sources of access-control and input-validation weaknesses. Current severity, exploitation activity, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Smoothwall over time
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-0209HIGH Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to execute arbitrary code via large sequence numbers in packets, wh | May 5, 2003 | 10.0 | 56 | NO | YES |
CVE-2011-5284MEDIUM Cross-site request forgery (CSRF) vulnerability in the web management interface in httpd/cgi-bin/shutdown.cgi in Smoothwall Express 3.1 and 3.0 SP3 and earlier allows remote attack | Dec 31, 2014 | 6.8 | 32 | NO | YES |
CVE-2011-1085HIGH CSRF vulnerability in Smoothwall Express 3. | Feb 7, 2020 | 8.8 | 28 | NO | NO |
CVE-2011-5283MEDIUM Cross-site scripting (XSS) vulnerability in the web management interface in httpd/cgi-bin/ipinfo.cgi in Smoothwall Express 3.1 and 3.0 SP3 and earlier allows remote attackers to in | Dec 31, 2014 | 4.3 | 26 | NO | YES |
CVE-2019-25395MEDIUM Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple stored cross-site scripting vulnerabilities in the preferences.cgi script that allow attackers to inject malicious | Feb 16, 2026 | 6.1 | 23 | NO | NO |
CVE-2019-25379HIGH Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains stored and reflected cross-site scripting vulnerabilities in the urlfilter.cgi endpoint that allow attackers to inject mali | Feb 16, 2026 | 7.2 | 23 | NO | NO |
CVE-2026-27508MEDIUM Smoothwall Express versions prior to 3.1 Update 13 contain a reflected cross-site scripting vulnerability in the /redirect.cgi endpoint due to improper sanitation of the url parame | Mar 30, 2026 | 6.1 | 22 | NO | NO |
CVE-2019-25381MEDIUM Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the hosts.cgi script that allow attackers to inject malicious sc | Feb 16, 2026 | 6.1 | 22 | NO | NO |
CVE-2026-26352MEDIUM Smoothwall Express versions prior to 3.1 Update 13 contain a stored cross-site scripting vulnerability in the /cgi-bin/vpnmain.cgi script due to improper sanitation of the VPN_IP p | Mar 30, 2026 | 5.4 | 21 | NO | NO |
CVE-2019-25394MEDIUM Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple stored cross-site scripting vulnerabilities in the modem.cgi script that allow attackers to inject malicious scrip | Feb 16, 2026 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Smoothwall.
Media articles that mention a CVE ID that affects a product developed by Smoothwall — matched by CVE ID, not by vendor name.