Smoothwall Express

Vendor:

First CVE: Feb 7, 2020 · Active for 6 years

21
Total CVEs
More Total CVEs than 94% of tracked products
10.5
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Smoothwall Express over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 7, 2020
6 years ago
Most Recent CVE
Mar 30, 2026
118 days ago

CVE Severity & Scoring

Smoothwall Express21 CVEs
All CVEs352,713 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network21 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (4.8%)
Unknown0 (0.0%)
Required20 (95.2%)
Privileges Required
Low1 (4.8%)
High0 (0.0%)
None20 (95.2%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CSRF vulnerability in Smoothwall Express 3.
Feb 7, 20208.828NONO
Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple stored cross-site scripting vulnerabilities in the preferences.cgi script that allow attackers to inject malicious
Feb 16, 20266.123NONO
Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains stored and reflected cross-site scripting vulnerabilities in the urlfilter.cgi endpoint that allow attackers to inject mali
Feb 16, 20267.223NONO
Smoothwall Express versions prior to 3.1 Update 13 contain a reflected cross-site scripting vulnerability in the /redirect.cgi endpoint due to improper sanitation of the url parame
Mar 30, 20266.122NONO
Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the hosts.cgi script that allow attackers to inject malicious sc
Feb 16, 20266.122NONO
Smoothwall Express versions prior to 3.1 Update 13 contain a stored cross-site scripting vulnerability in the /cgi-bin/vpnmain.cgi script due to improper sanitation of the VPN_IP p
Mar 30, 20265.421NONO
Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple stored cross-site scripting vulnerabilities in the modem.cgi script that allow attackers to inject malicious scrip
Feb 16, 20266.121NONO
Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploit
Feb 16, 20266.121NONO
Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipul
Feb 16, 20266.121NONO
Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the interfaces.cgi script that allow attackers to inject malicio
Feb 16, 20266.121NONO

Exploit Exposure

Signals from CVEs in this product scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (21 CVEs).

Media Mentions

Signals from CVEs in this product scope (21 CVEs).

Top CNAs Publishing CVEs For Smoothwall Express

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.1195.90.2%00
3.027.50.5%00