CVE-2025-2274

medium Forcepoint
CVSS v3 Base Score
4.8
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Attack Characteristics
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
A
Published: March 16, 2026 (58 days ago)
Last Modified: March 16, 2026
Vendor: Forcepoint
Source: MITRE

Description

Improper Neutralization of Input During Web Page Generation in Forcepoint Web Security (On-Prem) on Windows allows Stored XSS.This issue affects Web Security through 8.5.6.

CWE

CWE-79

Affected Products

Forcepoint Web Security (On-Prem)

References