CVE-2025-4804EPSS p34.2%

CVE-2025-4804CVE-2025-4804

Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the spamBlocker module. This vulnerability requires an authenticated administrator session to a locally managed Firebox.

Scoring

EPSS0.41% probability of exploitation · percentile 34.2% · 2026-08-08T12:02:54Z
Last modified2026-08-08
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.