Ipfire records
32 published records for vendor ipfire.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 6.3%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')25
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')5
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
32 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
53Plan | CVE-2021-33393Weaponized | lfs/backup in IPFire 2.25-core155 does not ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account.ipfire · ipfire | High8.8 | — | 59.6% | Jun 9, 2021 |
46Plan | CVE-2017-9757Weaponized | IPFire 2.19 has a Remote Command Injection vulnerability in ids.cgi via the OINKCODE parameter, which is mishandled by a shell.ipfire · ipfire · CWE-78 | High8.8 | — | 37.2% | Jun 19, 2017 |
38Monitor | CVE-2025-34311No exploit | IPFire < v2.29 Command Injection via Proxy Report Creationipfire · ipfire · CWE-78 | High8.7 | — | 13.5% | Oct 28, 2025 |
37Monitor | CVE-2018-16232No exploit | An authenticated command injection vulnerability exists in IPFire Firewall before 2.21 Core Update 124 in backup.cgi.ipfire · ipfire · CWE-78 | High8.8 | — | 7.8% | Oct 17, 2018 |
35Monitor | CVE-2025-34312No exploit | IPFire < v2.29 Command Injection via URL Filter Blacklistipfire · ipfire · CWE-78 | High8.7 | — | 2.2% | Oct 28, 2025 |
28Monitor | CVE-2025-34304No exploit | IPFire < v2.29 SQL Injection via OpenVPN Connection Logsipfire · ipfire · CWE-89 | High7.1 | — | 0.4% | Oct 28, 2025 |
26Monitor | CVE-2025-50974No exploit | The Calamaris log exporter CGI (/cgi-bin/logs.cgi/calamaris.dat) in IPFire 2.29 does not properly sanitize user-supplied input before incorpipfire · ipfire · CWE-78 | Medium6.5 | — | 0.4% | Aug 26, 2025 |
24Monitor | CVE-2020-21142No exploit | Cross Site Scripting (XSS) vulnerabilty in IPFire 2.23 via the IPfire web UI in the mail.cgi.ipfire · ipfire · CWE-79 | Medium6.1 | — | 0.7% | Jun 28, 2021 |
24Monitor | CVE-2025-50976No exploit | IPFire 2.29 DNS management interface (dns.cgi) fails to properly sanitize user-supplied input in the NAMESERVER, REMARK, and TLS_HOSTNAME quipfire · ipfire · CWE-79 | Medium6.1 | — | 0.2% | Aug 26, 2025 |
22Monitor | CVE-2025-34301No exploit | IPFire < v2.29 Stored XSS via Location Group Creationipfire · ipfire · CWE-79 | Medium5.1 | — | 5.3% | Oct 28, 2025 |
22Monitor | CVE-2025-34309No exploit | IPFire < v2.29 Stored XSS via Dynamic DNS Hostipfire · ipfire · CWE-79 | Medium5.1 | — | 5.3% | Oct 28, 2025 |
21Monitor | CVE-2020-19204No exploit | An authenticated Stored Cross-Site Scriptiong (XSS) vulnerability exists in Lightning Wire Labs IPFire 2.21 (x86_64) - Core Update 130 in thipfire · ipfire · CWE-79 | Medium5.4 | — | 0.7% | Jul 12, 2021 |
21Monitor | CVE-2020-19202No exploit | An authenticated Stored XSS (Cross-site Scripting) exists in the "captive.cgi" Captive Portal via the "Title of Login Page" text box or "TITipfire · ipfire · CWE-79 | Medium5.4 | — | 0.6% | Jun 17, 2021 |
21Monitor | CVE-2025-50975No exploit | IPFire 2.29 web-based firewall interface (firewall.cgi) fails to sanitize several rule parameters such as PROT, SRC_PORT, TGT_PORT, dnatportipfire · ipfire · CWE-79 | Medium5.4 | — | 0.3% | Aug 26, 2025 |
20Monitor | CVE-2025-34303No exploit | IPFire < v2.29 Stored XSS via Whitelisted Host Creationipfire · ipfire · CWE-79 | Medium5.1 | — | 0.5% | Oct 28, 2025 |
20Monitor | CVE-2025-34305No exploit | IPFire < v2.29 Stored XSS via Multiple Methods in cleanhtml()ipfire · ipfire · CWE-79 | Medium5.1 | — | 0.5% | Oct 28, 2025 |
20Monitor | CVE-2025-34306No exploit | IPFire < v2.29 Stored XSS via Default IP Search Valueipfire · ipfire · CWE-79 | Medium5.1 | — | 0.5% | Oct 28, 2025 |
20Monitor | CVE-2025-34307No exploit | IPFire < v2.29 Stored XSS via Default Country Searchipfire · ipfire · CWE-79 | Medium5.1 | — | 0.5% | Oct 28, 2025 |
20Monitor | CVE-2025-34308No exploit | IPFire < v2.29 Stored XSS via Default Time Syncipfire · ipfire · CWE-79 | Medium5.1 | — | 0.5% | Oct 28, 2025 |
20Monitor | CVE-2025-34310No exploit | IPFire < v2.29 Stored XSS via Quality of Service (QoS) Settingsipfire · ipfire · CWE-79 | Medium5.1 | — | 0.5% | Oct 28, 2025 |
20Monitor | CVE-2025-34317No exploit | IPFire < v2.29 Stored XSS via DNS Creation (dns.cgi)ipfire · ipfire · CWE-79 | Medium5.1 | — | 0.5% | Oct 28, 2025 |
20Monitor | CVE-2025-34302No exploit | IPFire < v2.29 Stored XSS via Service Creationipfire · ipfire · CWE-79 | Medium5.1 | — | 0.5% | Oct 28, 2025 |
20Monitor | CVE-2025-34314No exploit | IPFire < v2.29 Stored XSS via Time Constraint Rule URL Filteripfire · ipfire · CWE-79 | Medium5.1 | — | 0.5% | Oct 28, 2025 |
20Monitor | CVE-2025-34315No exploit | IPFire < v2.29 Stored XSS via Remote Syslog Server Addressipfire · ipfire · CWE-79 | Medium5.1 | — | 0.5% | Oct 28, 2025 |
20Monitor | CVE-2025-34316No exploit | IPFire < v2.29 Stored XSS via Mail Server Settingsipfire · ipfire · CWE-79 | Medium5.1 | — | 0.5% | Oct 28, 2025 |
- CVE-2021-3339353Plan
lfs/backup in IPFire 2.25-core155 does not ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account.
HighCVSS 8.8WeaponizedEPSS 60%ipfire · ipfireJun 9, 2021
- CVE-2017-975746Plan
IPFire 2.19 has a Remote Command Injection vulnerability in ids.cgi via the OINKCODE parameter, which is mishandled by a shell.
HighCVSS 8.8WeaponizedEPSS 37%ipfire · ipfireJun 19, 2017
- CVE-2025-3431138Monitor
IPFire < v2.29 Command Injection via Proxy Report Creation
HighCVSS 8.7No exploitEPSS 13%ipfire · ipfireOct 28, 2025
- CVE-2018-1623237Monitor
An authenticated command injection vulnerability exists in IPFire Firewall before 2.21 Core Update 124 in backup.cgi.
HighCVSS 8.8No exploitEPSS 8%ipfire · ipfireOct 17, 2018
- CVE-2025-3431235Monitor
IPFire < v2.29 Command Injection via URL Filter Blacklist
HighCVSS 8.7No exploitEPSS 2%ipfire · ipfireOct 28, 2025
- CVE-2025-3430428Monitor
IPFire < v2.29 SQL Injection via OpenVPN Connection Logs
HighCVSS 7.1No exploitEPSS 0%ipfire · ipfireOct 28, 2025
- CVE-2025-5097426Monitor
The Calamaris log exporter CGI (/cgi-bin/logs.cgi/calamaris.dat) in IPFire 2.29 does not properly sanitize user-supplied input before incorp
MediumCVSS 6.5No exploitEPSS 0%ipfire · ipfireAug 26, 2025
- CVE-2020-2114224Monitor
Cross Site Scripting (XSS) vulnerabilty in IPFire 2.23 via the IPfire web UI in the mail.cgi.
MediumCVSS 6.1No exploitEPSS 1%ipfire · ipfireJun 28, 2021
- CVE-2025-5097624Monitor
IPFire 2.29 DNS management interface (dns.cgi) fails to properly sanitize user-supplied input in the NAMESERVER, REMARK, and TLS_HOSTNAME qu
MediumCVSS 6.1No exploitEPSS 0%ipfire · ipfireAug 26, 2025
- CVE-2025-3430122Monitor
IPFire < v2.29 Stored XSS via Location Group Creation
MediumCVSS 5.1No exploitEPSS 5%ipfire · ipfireOct 28, 2025
- CVE-2025-3430922Monitor
IPFire < v2.29 Stored XSS via Dynamic DNS Host
MediumCVSS 5.1No exploitEPSS 5%ipfire · ipfireOct 28, 2025
- CVE-2020-1920421Monitor
An authenticated Stored Cross-Site Scriptiong (XSS) vulnerability exists in Lightning Wire Labs IPFire 2.21 (x86_64) - Core Update 130 in th
MediumCVSS 5.4No exploitEPSS 1%ipfire · ipfireJul 12, 2021
- CVE-2020-1920221Monitor
An authenticated Stored XSS (Cross-site Scripting) exists in the "captive.cgi" Captive Portal via the "Title of Login Page" text box or "TIT
MediumCVSS 5.4No exploitEPSS 1%ipfire · ipfireJun 17, 2021
- CVE-2025-5097521Monitor
IPFire 2.29 web-based firewall interface (firewall.cgi) fails to sanitize several rule parameters such as PROT, SRC_PORT, TGT_PORT, dnatport
MediumCVSS 5.4No exploitEPSS 0%ipfire · ipfireAug 26, 2025
- CVE-2025-3430320Monitor
IPFire < v2.29 Stored XSS via Whitelisted Host Creation
MediumCVSS 5.1No exploitEPSS 0%ipfire · ipfireOct 28, 2025
- CVE-2025-3430520Monitor
IPFire < v2.29 Stored XSS via Multiple Methods in cleanhtml()
MediumCVSS 5.1No exploitEPSS 0%ipfire · ipfireOct 28, 2025
- CVE-2025-3430620Monitor
IPFire < v2.29 Stored XSS via Default IP Search Value
MediumCVSS 5.1No exploitEPSS 0%ipfire · ipfireOct 28, 2025
- CVE-2025-3430720Monitor
IPFire < v2.29 Stored XSS via Default Country Search
MediumCVSS 5.1No exploitEPSS 0%ipfire · ipfireOct 28, 2025
- CVE-2025-3430820Monitor
IPFire < v2.29 Stored XSS via Default Time Sync
MediumCVSS 5.1No exploitEPSS 0%ipfire · ipfireOct 28, 2025
- CVE-2025-3431020Monitor
IPFire < v2.29 Stored XSS via Quality of Service (QoS) Settings
MediumCVSS 5.1No exploitEPSS 0%ipfire · ipfireOct 28, 2025
- CVE-2025-3431720Monitor
IPFire < v2.29 Stored XSS via DNS Creation (dns.cgi)
MediumCVSS 5.1No exploitEPSS 0%ipfire · ipfireOct 28, 2025
- CVE-2025-3430220Monitor
IPFire < v2.29 Stored XSS via Service Creation
MediumCVSS 5.1No exploitEPSS 0%ipfire · ipfireOct 28, 2025
- CVE-2025-3431420Monitor
IPFire < v2.29 Stored XSS via Time Constraint Rule URL Filter
MediumCVSS 5.1No exploitEPSS 0%ipfire · ipfireOct 28, 2025
- CVE-2025-3431520Monitor
IPFire < v2.29 Stored XSS via Remote Syslog Server Address
MediumCVSS 5.1No exploitEPSS 0%ipfire · ipfireOct 28, 2025
- CVE-2025-3431620Monitor
IPFire < v2.29 Stored XSS via Mail Server Settings
MediumCVSS 5.1No exploitEPSS 0%ipfire · ipfireOct 28, 2025