CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 4.8. See the original NVD description below for full technical details.
CVE
CVE-2026-13376
Severity
MEDIUM
CVSS
4.8
EPSS
0.16%
Original NVD Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS spamBlocker module allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-1071. This issue affects Fireware OS 12.0 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.
Related CVEs
Other vulnerabilities affecting the same vendor(s)