FXE3000-WP vulnerabilities
CVEs whose affected-version data names the FXE3000-WP package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-82763Medium· 5.4Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series
Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
CVE-2026-82764Medium· 4.3Cross-site request forgery vulnerability exists in multiple Contec products
Cross-site request forgery vulnerability exists in multiple Contec products. If a user views a specially crafted page while logged in to the affected product, unintended operations may be performed.
CVE-2026-82762High· 8.8Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000 series
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary OS command may be execute…
CVE-2026-82765High· 8.1Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series
Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.