CVE-2025-4804EPSS p36.6%

CVE-2025-4804CVE-2025-4804

Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the spamBlocker module. This vulnerability requires an authenticated administrator session to a locally managed Firebox.

Scoring

EPSS0.45% probability of exploitation · percentile 36.6% · 2026-10-06T12:00:23Z
Last modified2026-08-08
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.