Skip to content
Noroxi

Ipfire records

32 published records for vendor ipfire.

Researcher profile

Entered KEV
0 · 0%
Weaponized
2 · 6.3%
Pre-auth RCE
4
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

32 records
  • lfs/backup in IPFire 2.25-core155 does not ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account.

    HighCVSS 8.8WeaponizedEPSS 60%

    ipfire · ipfireJun 9, 2021

  • IPFire 2.19 has a Remote Command Injection vulnerability in ids.cgi via the OINKCODE parameter, which is mishandled by a shell.

    HighCVSS 8.8WeaponizedEPSS 37%

    ipfire · ipfireJun 19, 2017

  • IPFire < v2.29 Command Injection via Proxy Report Creation

    HighCVSS 8.7No exploitEPSS 13%

    ipfire · ipfireOct 28, 2025

  • An authenticated command injection vulnerability exists in IPFire Firewall before 2.21 Core Update 124 in backup.cgi.

    HighCVSS 8.8No exploitEPSS 8%

    ipfire · ipfireOct 17, 2018

  • IPFire < v2.29 Command Injection via URL Filter Blacklist

    HighCVSS 8.7No exploitEPSS 2%

    ipfire · ipfireOct 28, 2025

  • IPFire < v2.29 SQL Injection via OpenVPN Connection Logs

    HighCVSS 7.1No exploitEPSS 0%

    ipfire · ipfireOct 28, 2025

  • The Calamaris log exporter CGI (/cgi-bin/logs.cgi/calamaris.dat) in IPFire 2.29 does not properly sanitize user-supplied input before incorp

    MediumCVSS 6.5No exploitEPSS 0%

    ipfire · ipfireAug 26, 2025

  • Cross Site Scripting (XSS) vulnerabilty in IPFire 2.23 via the IPfire web UI in the mail.cgi.

    MediumCVSS 6.1No exploitEPSS 1%

    ipfire · ipfireJun 28, 2021

  • IPFire 2.29 DNS management interface (dns.cgi) fails to properly sanitize user-supplied input in the NAMESERVER, REMARK, and TLS_HOSTNAME qu

    MediumCVSS 6.1No exploitEPSS 0%

    ipfire · ipfireAug 26, 2025

  • IPFire < v2.29 Stored XSS via Location Group Creation

    MediumCVSS 5.1No exploitEPSS 5%

    ipfire · ipfireOct 28, 2025

  • IPFire < v2.29 Stored XSS via Dynamic DNS Host

    MediumCVSS 5.1No exploitEPSS 5%

    ipfire · ipfireOct 28, 2025

  • An authenticated Stored Cross-Site Scriptiong (XSS) vulnerability exists in Lightning Wire Labs IPFire 2.21 (x86_64) - Core Update 130 in th

    MediumCVSS 5.4No exploitEPSS 1%

    ipfire · ipfireJul 12, 2021

  • An authenticated Stored XSS (Cross-site Scripting) exists in the "captive.cgi" Captive Portal via the "Title of Login Page" text box or "TIT

    MediumCVSS 5.4No exploitEPSS 1%

    ipfire · ipfireJun 17, 2021

  • IPFire 2.29 web-based firewall interface (firewall.cgi) fails to sanitize several rule parameters such as PROT, SRC_PORT, TGT_PORT, dnatport

    MediumCVSS 5.4No exploitEPSS 0%

    ipfire · ipfireAug 26, 2025

  • IPFire < v2.29 Stored XSS via Whitelisted Host Creation

    MediumCVSS 5.1No exploitEPSS 0%

    ipfire · ipfireOct 28, 2025

  • IPFire < v2.29 Stored XSS via Multiple Methods in cleanhtml()

    MediumCVSS 5.1No exploitEPSS 0%

    ipfire · ipfireOct 28, 2025

  • IPFire < v2.29 Stored XSS via Default IP Search Value

    MediumCVSS 5.1No exploitEPSS 0%

    ipfire · ipfireOct 28, 2025

  • IPFire < v2.29 Stored XSS via Default Country Search

    MediumCVSS 5.1No exploitEPSS 0%

    ipfire · ipfireOct 28, 2025

  • IPFire < v2.29 Stored XSS via Default Time Sync

    MediumCVSS 5.1No exploitEPSS 0%

    ipfire · ipfireOct 28, 2025

  • IPFire < v2.29 Stored XSS via Quality of Service (QoS) Settings

    MediumCVSS 5.1No exploitEPSS 0%

    ipfire · ipfireOct 28, 2025

  • IPFire < v2.29 Stored XSS via DNS Creation (dns.cgi)

    MediumCVSS 5.1No exploitEPSS 0%

    ipfire · ipfireOct 28, 2025

  • IPFire < v2.29 Stored XSS via Service Creation

    MediumCVSS 5.1No exploitEPSS 0%

    ipfire · ipfireOct 28, 2025

  • IPFire < v2.29 Stored XSS via Time Constraint Rule URL Filter

    MediumCVSS 5.1No exploitEPSS 0%

    ipfire · ipfireOct 28, 2025

  • IPFire < v2.29 Stored XSS via Remote Syslog Server Address

    MediumCVSS 5.1No exploitEPSS 0%

    ipfire · ipfireOct 28, 2025

  • IPFire < v2.29 Stored XSS via Mail Server Settings

    MediumCVSS 5.1No exploitEPSS 0%

    ipfire · ipfireOct 28, 2025