Websense provides a portfolio of network security and content-filtering appliances, including V-Series endpoints and web-filtering solutions, that operate as chokepoints in enterprise traffic management. The vendor's vulnerability exposure is modestly represented in the landscape and concentrates across its filtering and inspection products through weakness classes including cross-site scripting, information disclosure, and memory-buffer handling issues—patterns typical of inspection-oriented appliances that parse and process untrusted content at scale. A moderate share of Websense vulnerabilities acquire public exploit code, reflecting the appeal of internet-deployed security appliances as targets for reconnaissance and bypass. Defenders should monitor this vendor's releases for its filtering and gateway products and treat discovered instances as candidates for timely remediation; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Websense over time
Signals from CVEs in this vendor scope (49 CVEs).
49 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-2746MEDIUM The network diagnostics tool (CommandLineServlet) in the Appliance Manager command line utility (CLU) in Websense TRITON 7.8.3 and V-Series appliances before 7.8.4 Hotfix 02 allows | Mar 26, 2015 | 6.5 | 41 | NO | YES |
CVE-2009-3749MEDIUM The Web Administrator service (STEMWADM.EXE) in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7.1 before Hotfix 4 allows remote attackers to cause a denial | Oct 22, 2009 | 5.0 | 25 | NO | YES |
CVE-2015-2767HIGH Unspecified vulnerability in Websense TRITON AP-EMAIL before 8.0.0 has unknown impact and attack vectors, related to "Autocomplete Enabled." | Mar 27, 2015 | 10.0 | 24 | NO | NO |
CVE-2015-2763HIGH Unspecified vulnerability in Websense TRITON AP-EMAIL before 8.0.0 has unknown impact and attack vectors, related to port 17703. | Mar 27, 2015 | 10.0 | 24 | NO | NO |
CVE-2012-2984MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in monitor/m_overview.ink in Websense Content Gateway before 7.7.3 allow remote attackers to inject arbitrary web script or HTML | Aug 24, 2012 | 4.3 | 24 | NO | YES |
CVE-2017-11177HIGH TRITON AP-EMAIL 8.2 before 8.2 IB does not properly restrict file access in an unspecified directory. | Nov 6, 2017 | 7.5 | 23 | NO | NO |
CVE-2011-5102HIGH The Investigative Reports web interface in the TRITON management console in Websense Web Security 7.1 before Hotfix 109, 7.1.1 before Hotfix 06, 7.5 before Hotfix 78, 7.5.1 before | Aug 23, 2012 | 7.5 | 23 | NO | NO |
CVE-2009-3748MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the Web Administrator in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7.1 before Hotfix 4 allow rem | Oct 22, 2009 | 4.3 | 22 | NO | YES |
CVE-2012-4605MEDIUM The default configuration of the SMTP component in Websense Email Security 6.1 through 7.3 enables weak SSL ciphers in the "SurfControl plc\SuperScout Email Filter\SMTP" registry k | Aug 23, 2012 | 5.0 | 20 | NO | NO |
CVE-2007-6312MEDIUM Cross-site scripting (XSS) vulnerability in the logon page in Web Reporting Tools portal in Websense Enterprise and Web Security Suite 6.3 allows remote attackers to inject arbitra | Dec 11, 2007 | 4.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (49 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Websense.
Media articles that mention a CVE ID that affects a product developed by Websense — matched by CVE ID, not by vendor name.