VendorsWatchGuardfirewareall versions
Vulnerabilities

WatchGuard Fireware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

61CVEs
CVE-2017-14615
An FBX-5313 issue was discovered in WatchGuard Fireware before 12.0. When a failed login attempt is made to the login endpoint of the XML-RPC interface, if JavaScript code, properly encoded to be consumed by XML parsers, is embedded as value of the user element, the code will be rendered in the context of any logged in user in the Web UI visiting "Traffic Monitor" sections "Events" and "All." As a side effect, no further events will be visible in the Traffic Monitor until the device is restarted.
Published 2017-09-20 · Modified
6.1EPSS 0.010
CVE-2016-6154
The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open redirect).
Published 2019-08-23 · Modified
6.1EPSS 0.009
CVE-2026-3343
WatchGuard Firebox Reflected Cross-Site-Scripting (XSS) Vulnerability in Fireware Web UI
Published 2026-03-03 · Modified
6.1EPSS 0.003
CVE-2025-0178
WatchGaurd Firebox Host Header Injection Vulnerability
Published 2025-02-14 · Modified
6.1EPSS 0.002
CVE-2025-13939
WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Gateway Wireless Controller
Published 2025-12-04 · Modified
6.1EPSS 0.002
CVE-2025-13938
WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Autotask Technology Integration Configuration
Published 2025-12-04 · Modified
6.1EPSS 0.002
CVE-2025-13937
WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in ConnectWise Technology Integration Configuration
Published 2025-12-04 · Modified
6.1EPSS 0.002
CVE-2025-13936
WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Tigerpaw Technology Integration Configuration
Published 2025-12-04 · Modified
6.1EPSS 0.002
CVE-2026-13728
WatchGuard Firebox Hardcoded Fallback Encryption Key in Access Portal Resource Credential Database
Published 2026-07-02 · Modified
5.9EPSS 0.002
CVE-2022-31792
A stored cross-site scripting (XSS) vulnerability exists in the management web interface of WatchGuard Firebox and XTM appliances. A remote attacker can potentially execute arbitrary JavaScript code in the management web interface by sending crafted requests to exposed management ports. This is fixed in Fireware OS 12.8.1, 12.5.10, and 12.1.4.
Published 2022-09-06 · Modified
5.4EPSS 0.006
CVE-2017-8056
WatchGuard Fireware v11.12.1 and earlier mishandles requests referring to an XML External Entity (XXE), in the XML-RPC agent. This causes the Firebox wgagent process to crash. This process crash ends all authenticated sessions to the Firebox, including management connections, and prevents new authenticated sessions until the process has recovered. The Firebox may also experience an overall degradation in performance while the wgagent process recovers. An attacker could continuously send XML-RPC requests that contain references to external entities to perform a limited Denial of Service (DoS) attack against an affected Firebox.
Published 2017-04-22 · Modified
5.3EPSS 0.051
CVE-2017-8055
WatchGuard Fireware allows user enumeration, e.g., in the Firebox XML-RPC login handler. A login request that contains a blank password sent to the XML-RPC agent in Fireware v11.12.1 and earlier returns different responses for valid and invalid usernames. An attacker could exploit this vulnerability to enumerate valid usernames on an affected Firebox.
Published 2017-04-22 · Modified
5.3EPSS 0.016
CVE-2025-1071
WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in spamBlocker Module
Published 2025-02-14 · Modified
4.8EPSS 0.003
CVE-2026-13377
WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in SIP Proxy Configuration
Published 2026-07-02 · Modified
4.8EPSS 0.003
CVE-2026-13376
WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in spamBlocker Module
Published 2026-07-02 · Modified
4.8EPSS 0.003
CVE-2026-13375
WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Autotask Technology Integration Configuration
Published 2026-07-02 · Modified
4.8EPSS 0.003
CVE-2026-13374
WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in ConnectWise Technology Integration Configuration
Published 2026-07-02 · Modified
4.8EPSS 0.003
CVE-2026-13373
WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Tigerpaw Technology Integration Configuration
Published 2026-07-02 · Modified
4.8EPSS 0.003
CVE-2025-6946
WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in IPS Configuration
Published 2025-12-04 · Modified
4.8EPSS 0.002
CVE-2014-0338
Multiple cross-site scripting (XSS) vulnerabilities in the firewall policy management pages in WatchGuard Fireware XTM before 11.8.3 allow remote attackers to inject arbitrary web script or HTML via the pol_name parameter.
Published 2014-03-16 · Modified
4.3EPSS 0.016
CVE-2013-5702
Multiple cross-site scripting (XSS) vulnerabilities in WebCenter in WatchGuard WSM and Fireware before 11.8 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.
Published 2013-10-19 · Modified
4.3EPSS 0.010
← Prev2 / 2