cbcvebase.

Watchguard Fireware vulnerabilities

70 known vulnerabilities affecting watchguard/fireware.

Total CVEs
70
CISA KEV
4
actively exploited
Public exploits
3
Exploited in wild
4
Severity breakdown
CRITICAL7HIGH35MEDIUM28

Vulnerabilities

Page 4 of 4
CVE-2026-13375P4MEDIUMCVSS 4.8≥ 12.4, < 12.12.1≥ 2025.1, < 2026.2.1+1 more2026-07-03
CVE-2026-13375 [MEDIUM] CVE-2026-13375: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13938. This issue affects Fireware OS 12.4 up to and including 12.12, 12.5 up to and includi
nvd
CVE-2026-13728P4MEDIUMCVSS 4.4≥ 12.1, < 12.12.1≥ 2025.1, < 2026.2.12026-07-03
CVE-2026-13728 [MEDIUM] CWE-798 CVE-2026-13728: In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved credentials for Access Portal resources. This vulnerability does not affect devices that do not support the Access Portal feature or standalone Fireboxes not deployed in a FireCluster.
nvd
CVE-2016-6154P4MEDIUMCVSS 6.1≤ 11.112019-08-23
CVE-2016-6154 [MEDIUM] CWE-79 CVE-2016-6154: The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open redirect).
nvd
CVE-2026-13377P4MEDIUMCVSS 4.8≥ 12.0, < 12.12.1≥ 2025.1, < 2026.2.1+1 more2026-07-03
CVE-2026-13377 [MEDIUM] CVE-2026-13377: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS SIP Proxy module allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-6947.
nvd
CVE-2026-13374P4MEDIUMCVSS 4.8≥ 12.4, < 12.12.1≥ 2025.1, < 2026.2.1+1 more2026-07-03
CVE-2026-13374 [MEDIUM] CVE-2026-13374: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13937.
nvd
CVE-2026-13373P4MEDIUMCVSS 4.8≥ 12.4, < 12.12.1≥ 2025.1, < 2026.2.1+1 more2026-07-03
CVE-2026-13373 [MEDIUM] CVE-2026-13373: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Tigerpaw Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13936.
nvd
CVE-2025-6946P4MEDIUMCVSS 4.8≥ 12.0.0, < 12.11.3≥ 12.5, < 12.5.132025-12-04
CVE-2025-6946 [MEDIUM] CWE-79 CVE-2025-6946: A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard F A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the IPS configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management ninterface of another management user.
nvd
CVE-2025-1071P4MEDIUMCVSS 4.8≥ 12.0.0, < 12.11.1≥ 12.5, < 12.5.132025-02-14
CVE-2025-1071 [MEDIUM] CWE-79 CVE-2025-1071: A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard F A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the spamBlocker module. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user.
nvd
CVE-2014-0338P4MEDIUMCVSS 4.3≤ 11.8.1v11.6+9 more2014-03-16
CVE-2014-0338 [MEDIUM] CWE-79 CVE-2014-0338: Multiple cross-site scripting (XSS) vulnerabilities in the firewall policy management pages in Watch Multiple cross-site scripting (XSS) vulnerabilities in the firewall policy management pages in WatchGuard Fireware XTM before 11.8.3 allow remote attackers to inject arbitrary web script or HTML via the pol_name parameter.
nvd
CVE-2013-5702P4MEDIUMCVSS 4.3≤ 11.7.4v11.6+7 more2013-10-19
CVE-2013-5702 [MEDIUM] CWE-79 CVE-2013-5702: Multiple cross-site scripting (XSS) vulnerabilities in WebCenter in WatchGuard WSM and Fireware befo Multiple cross-site scripting (XSS) vulnerabilities in WebCenter in WatchGuard WSM and Fireware before 11.8 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.
nvd
Watchguard Fireware vulnerabilities | cvebase