CVE-2026-27508

Severity CVSS v4.0:
MEDIUM
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
30/03/2026
Last modified:
14/04/2026

Description

Smoothwall Express versions prior to 3.1 Update 13 contain a reflected cross-site scripting vulnerability in the /redirect.cgi endpoint due to improper sanitation of the url parameter. Attackers can craft malicious URLs with javascript: schemes that execute arbitrary JavaScript in victims' browsers when clicked through the unsanitized link.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:smoothwall:smoothwall_express:*:*:*:*:*:*:*:* 3.0 (including)
cpe:2.3:o:smoothwall:smoothwall_express:3.1:update1:*:*:-:*:*:*
cpe:2.3:o:smoothwall:smoothwall_express:3.1:update10:*:*:-:*:*:*
cpe:2.3:o:smoothwall:smoothwall_express:3.1:update11:*:*:-:*:*:*
cpe:2.3:o:smoothwall:smoothwall_express:3.1:update12:*:*:-:*:*:*
cpe:2.3:o:smoothwall:smoothwall_express:3.1:update2:*:*:-:*:*:*
cpe:2.3:o:smoothwall:smoothwall_express:3.1:update3:*:*:-:*:*:*
cpe:2.3:o:smoothwall:smoothwall_express:3.1:update4:*:*:-:*:*:*
cpe:2.3:o:smoothwall:smoothwall_express:3.1:update5:*:*:-:*:*:*
cpe:2.3:o:smoothwall:smoothwall_express:3.1:update6:*:*:-:*:*:*
cpe:2.3:o:smoothwall:smoothwall_express:3.1:update7:*:*:-:*:*:*
cpe:2.3:o:smoothwall:smoothwall_express:3.1:update8:*:*:-:*:*:*
cpe:2.3:o:smoothwall:smoothwall_express:3.1:update9:*:*:-:*:*:*