← Vulnerability feed

Vulnerability record · CVE-2025-34306 · published 28 October 2025

CVE-2025-34306: Ipfire cross-site scripting vulnerability

Ipfire · Ipfire

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject arbitrary JavaScript code through the pienumber parameter when updating the default firewall IP search values. When a user updates these defaults, the application issues an HTTP POST request to /cgi-bin/logs.cgi/firewalllogip.dat with the default number of IPs in the pienumber parameter. The value of this parameter is stored and later rendered in the web interface without proper sanitation or encoding, allowing injected scripts to execute in the context of other users who view the affected page.

5.1 CVSS 4.0 Medium EPSS 0.49% · top 60.5% CWE-79 · Cross-site scripting
5.1CVSS 4.0 base score
0.49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject arbitrary JavaScript code through the pienumber parameter when updating the default firewall IP search values. When a user updates these defaults, the application issues an HTTP POST request to /cgi-bin/logs.cgi/firewalllogip.dat with the default number of IPs in the pienumber parameter. The value of this parameter is stored and later rendered in the web interface without proper sanitation or encoding, allowing injected scripts to execute in the context of other users who view the affected page.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-34306 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2021-33393IPFire backup script ownership flaw enables root code executionIPFire 2.25-core155 does not verify that /var/ipfire/backup/bin/backup.pl is owned by root, so the file may be writable by an unprivileged account. A…EPSS 60%analysed8.8CVE-2018-16232Ipfire os command injection vulnerabilityAn authenticated command injection vulnerability exists in IPFire Firewall before 2.21 Core Update 124 in backup.cgi. This allows an authenticated us…EPSS 7.8%8.8CVE-2017-9757Ipfire os command injection vulnerabilityIPFire 2.19 has a Remote Command Injection vulnerability in ids.cgi via the OINKCODE parameter, which is mishandled by a shell. This can be exploited…EPSS 37%8.7CVE-2025-34311Ipfire os command injection vulnerabilityIPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary …EPSS 13%8.7CVE-2025-34312Ipfire os command injection vulnerabilityIPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary …EPSS 2.2%7.1CVE-2025-34304Ipfire sql injection vulnerabilityIPFire versions prior to 2.29 (Core Update 198) contain a SQL injection vulnerability that allows an authenticated attacker to manipulate the SQL que…EPSS 0.42%6.5CVE-2025-50974Ipfire os command injection vulnerabilityThe Calamaris log exporter CGI (/cgi-bin/logs.cgi/calamaris.dat) in IPFire 2.29 does not properly sanitize user-supplied input before incorporating p…EPSS 0.40%6.1CVE-2025-50976Ipfire cross-site scripting vulnerabilityIPFire 2.29 DNS management interface (dns.cgi) fails to properly sanitize user-supplied input in the NAMESERVER, REMARK, and TLS_HOSTNAME query param…EPSS 0.23%

Source: NIST National Vulnerability Database (record CVE-2025-34306), CISA KEV, FIRST EPSS (scores of 2026-10-01). This page is refreshed as NVD updates the record.