Vulnerability Database

308,926

Total vulnerabilities in the database

CVE-2022-36368

Multiple stored cross-site scripting vulnerabilities in the web user interface of IPFire versions prior to 2.27 allows a remote authenticated attacker with administrative privilege to inject an arbitrary script.

  • Published: Oct 24, 2022
  • Updated: Nov 16, 2025
  • CVE: CVE-2022-36368
  • Severity: Low
  • Exploit:

CVSS v3:

  • Severity: Low
  • Score: 4.8
  • AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Software From Fixed in
ipfire / ipfire 2.27-core_update160 2.27-core_update160.x
ipfire / ipfire 2.27-core_update161 2.27-core_update161.x
ipfire / ipfire 2.27-core_update162 2.27-core_update162.x
ipfire / ipfire 2.27-core_update163 2.27-core_update163.x
ipfire / ipfire 2.27-core_update164 2.27-core_update164.x
ipfire / ipfire 2.27-core_update165 2.27-core_update165.x
ipfire / ipfire 2.27-core_update166 2.27-core_update166.x
ipfire / ipfire 2.27-core_update167 2.27-core_update167.x
ipfire / ipfire 2.27-core_update159 2.27-core_update159.x
ipfire / ipfire - 2.27