
CVE-2026-34803 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the name parameter to /manage/qos/classes/. An authenticated attacker can inject … https://www.cve.org/CVERecord?id=CVE-2026-34803
Post summary
The post discloses CVE‑2026‑34803, a stored XSS flaw in Endian Firewall 3.3.25 and earlier, where authenticated users can inject payloads through the name parameter in /manage/qos/classes/.
