Smoothwall Express
Vendor:
First CVE: Feb 7, 2020 · Active for 6 years
21
Total CVEs
More Total CVEs than 94% of tracked products
10.5
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Smoothwall Express over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 7, 2020
6 years ago
Most Recent CVE
Mar 30, 2026
118 days ago
CVE Severity & Scoring
Smoothwall Express21 CVEs
90%
10%
All CVEs352,713 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network21 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (4.8%)
Unknown0 (0.0%)
Required20 (95.2%)
Privileges Required
Low1 (4.8%)
High0 (0.0%)
None20 (95.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-1085HIGH CSRF vulnerability in Smoothwall Express 3. | Feb 7, 2020 | 8.8 | 28 | NO | NO |
CVE-2019-25395MEDIUM Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple stored cross-site scripting vulnerabilities in the preferences.cgi script that allow attackers to inject malicious | Feb 16, 2026 | 6.1 | 23 | NO | NO |
CVE-2019-25379HIGH Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains stored and reflected cross-site scripting vulnerabilities in the urlfilter.cgi endpoint that allow attackers to inject mali | Feb 16, 2026 | 7.2 | 23 | NO | NO |
CVE-2026-27508MEDIUM Smoothwall Express versions prior to 3.1 Update 13 contain a reflected cross-site scripting vulnerability in the /redirect.cgi endpoint due to improper sanitation of the url parame | Mar 30, 2026 | 6.1 | 22 | NO | NO |
CVE-2019-25381MEDIUM Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the hosts.cgi script that allow attackers to inject malicious sc | Feb 16, 2026 | 6.1 | 22 | NO | NO |
CVE-2026-26352MEDIUM Smoothwall Express versions prior to 3.1 Update 13 contain a stored cross-site scripting vulnerability in the /cgi-bin/vpnmain.cgi script due to improper sanitation of the VPN_IP p | Mar 30, 2026 | 5.4 | 21 | NO | NO |
CVE-2019-25394MEDIUM Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple stored cross-site scripting vulnerabilities in the modem.cgi script that allow attackers to inject malicious scrip | Feb 16, 2026 | 6.1 | 21 | NO | NO |
CVE-2019-25393MEDIUM Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploit | Feb 16, 2026 | 6.1 | 21 | NO | NO |
CVE-2019-25392MEDIUM Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipul | Feb 16, 2026 | 6.1 | 21 | NO | NO |
CVE-2019-25390MEDIUM Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the interfaces.cgi script that allow attackers to inject malicio | Feb 16, 2026 | 6.1 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (21 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (21 CVEs).
Media Mentions
Signals from CVEs in this product scope (21 CVEs).
Top CNAs Publishing CVEs For Smoothwall Express
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.1 | 19 | 5.9 | 0.2% | 0 | 0 |
| 3.0 | 2 | 7.5 | 0.5% | 0 | 0 |