Ipfire-org
18 CVEs tracked since 2025. Since Oct 2025, none of them reached CISA KEV.
Ipfire-org CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2025-10 | 18 | 0 |
Products
The products that kept showing up in Ipfire-org's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Ipfire-org.
- CVE-2025-34311IPFire < v2.29 Command Injection via Proxy Report Creation8.8
- CVE-2025-34312IPFire < v2.29 Command Injection via URL Filter Blacklist8.8
- CVE-2025-34304IPFire < v2.29 SQL Injection via OpenVPN Connection Logs6.5
- CVE-2025-34307IPFire < v2.29 Stored XSS via Default Country Search5.4
- CVE-2025-34306IPFire < v2.29 Stored XSS via Default IP Search Value5.4
- CVE-2025-34308IPFire < v2.29 Stored XSS via Default Time Sync5.4
- CVE-2025-34318IPFire < v2.29 Stored XSS via DNS Creation (proxy.cgi)—
- CVE-2025-34317IPFire < v2.29 Stored XSS via DNS Creation (dns.cgi)5.4
- CVE-2025-34309IPFire < v2.29 Stored XSS via Dynamic DNS Host5.4
- CVE-2025-34301IPFire < v2.29 Stored XSS via Location Group Creation5.4
- CVE-2025-34316IPFire < v2.29 Stored XSS via Mail Server Settings5.4
- CVE-2025-34305IPFire < v2.29 Stored XSS via Multiple Methods in cleanhtml()5.4
- CVE-2025-34310IPFire < v2.29 Stored XSS via Quality of Service (QoS) Settings5.4
- CVE-2025-34315IPFire < v2.29 Stored XSS via Remote Syslog Server Address5.4
- CVE-2025-34302IPFire < v2.29 Stored XSS via Service Creation5.4
The record
- Peak rank
- #59 in Oct 2025
- Busiest month shown
- Oct 2025, 18 CVEs
- Months with a KEV entry
- 0 since Oct 2025
- Monthly snapshots
- 1 since 2025