Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Untangle Project

First CVE: Nov 14, 2019Active for: 7 yearsTotal CVEs: 7

Untangle Project develops a network security and gateway appliance platform with a focused product footprint centered on its core Untangle gateway application. The recurring vulnerability pattern centers on XML parsing weaknesses, specifically improper handling of recursive entity references and external entity inclusions in DTD processing, reflecting the complexities of XML-based configuration or data interchange in network appliances. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 56% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Untangle Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 14, 2019
6 years ago
Most Recent CVE
Jul 26, 2022
1,460 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-33977HIGH
untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts recursive entity references in DTDs. By exploiting this
Jul 26, 20227.524NONO
CVE-2022-31471HIGH
untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts XML external entity references. By exploiting this vuln
Jul 26, 20227.524NONO
CVE-2019-18647HIGH
The Untangle NG firewall 14.2.0 is vulnerable to an authenticated command injection when logged in as an admin user.
Nov 14, 20197.224NONO
CVE-2019-18646HIGH
The Untangle NG firewall 14.2.0 is vulnerable to authenticated inline-query SQL injection within the timeDataDynamicColumn parameter when logged in as an admin user.
Nov 14, 20197.223NONO
CVE-2019-18649MEDIUM
When logged in as an admin user, the Title input field (under Reports) within Untangle NG firewall 14.2.0 is vulnerable to stored XSS.
Nov 14, 20194.818NONO
CVE-2019-18648MEDIUM
When logged in as an admin user, the Untangle NG firewall 14.2.0 is vulnerable to reflected XSS at multiple places and specific user input fields.
Nov 14, 20194.818NONO
CVE-2020-17494MEDIUM
Untangle Firewall NG before 16.0 uses MD5 for passwords.
Nov 12, 20205.315NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
43%
57%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (71.4%)
Unknown0 (0.0%)
Required2 (28.6%)
Privileges Required
Low0 (0.0%)
High4 (57.1%)
None3 (42.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Untangle Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Untangle Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Untangle Project's Products

View all 2 CNAs →

Top CWEs