All 6 CVE vulnerabilities found in Express, with AI-generated Chinese analysis, references, and POCs.
Vendor: expressjs
| CVE ID | Title | CVSS | Severity | Paused |
|---|---|---|---|---|
| CVE-2026-27508 | Smoothwall Express < 3.1 Update 13 Reflected XSS in redirect.cgi via url Parameter CWE-79 | 5.4 | Medium | 2026-03-30 |
| CVE-2026-26352 | Smoothwall Express < 3.1 Update 13 Stored XSS in vpnmain.cgi via VPN_IP Parameter CWE-79 | 5.4 | Medium | 2026-03-30 |
| CVE-2024-10491 | Preload arbitrary resources by injecting additional `Link` headers CWE-74 | 4.0 | Medium | 2024-10-29 |
| CVE-2024-9266 | Open Redirect CWE-601 | 4.7 | Medium | 2024-10-03 |
| CVE-2024-43796 | express vulnerable to XSS via response.redirect() CWE-79 | 5.0 | Medium | 2024-09-10 |
| CVE-2024-29041 | Express.js Open Redirect in malformed URLs CWE-601 | 6.1 | Medium | 2024-03-25 |
All 6 known CVE vulnerabilities affecting Express with full Chinese analysis, references, and POCs where available.