CVE-2026-27508

EUVD-2026-17127
Smoothwall Express versions prior to 3.1 Update 13 contain a reflected cross-site scripting vulnerability in the /redirect.cgi endpoint due to improper sanitation of the url parameter. Attackers can craft malicious URLs with javascript: schemes that execute arbitrary JavaScript in victims' browsers when clicked through the unsanitized link.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.4 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 10%
Affected Products (NVD)
VendorProductVersion
smoothwallsmoothwall_express
𝑥
≤ 3.0
smoothwallsmoothwall_express
3.1:update1
smoothwallsmoothwall_express
3.1:update10
smoothwallsmoothwall_express
3.1:update11
smoothwallsmoothwall_express
3.1:update12
smoothwallsmoothwall_express
3.1:update2
smoothwallsmoothwall_express
3.1:update3
smoothwallsmoothwall_express
3.1:update4
smoothwallsmoothwall_express
3.1:update5
smoothwallsmoothwall_express
3.1:update6
smoothwallsmoothwall_express
3.1:update7
smoothwallsmoothwall_express
3.1:update8
smoothwallsmoothwall_express
3.1:update9
𝑥
= Vulnerable software versions