Untangle
untangle
5 CVEs • 2 products
Products (2)
Click to collapseToggle
Products (2)
Click to collapse
CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Untangle 1Untangle Firewall Ng Jun 17, 2026 Nov 12, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Untangle Firewall NG before 16.0 uses MD5 for passwords. |
When logged in as an admin user, the Title input field (under Reports) within Untangle NG firewall 14.2.0 is vulnerable to stored XSS. |
When logged in as an admin user, the Untangle NG firewall 14.2.0 is vulnerable to reflected XSS at multiple places and specific user input fields. |
The Untangle NG firewall 14.2.0 is vulnerable to an authenticated command injection when logged in as an admin user. |
The Untangle NG firewall 14.2.0 is vulnerable to authenticated inline-query SQL injection within the timeDataDynamicColumn parameter when logged in as an admin user. |