CVE-2026-27508

All FrameworksExpress.jsCWE-79CVE-2026-27508

CVE-2026-27508

State: PUBLISHED · Published: 2026-03-30 · Updated: 2026-03-31 · Assigner: VulnCheck
Description
Smoothwall Express versions prior to 3.1 Update 13 contain a reflected cross-site scripting vulnerability in the /redirect.cgi endpoint due to improper sanitation of the url parameter. Attackers can craft malicious URLs with javascript: schemes that execute arbitrary JavaScript in victims' browsers when clicked through the unsanitized link.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2026/27xxx/CVE-2026-27508.json