CVE-2026-97730
- EPSS 1.03%
- Veröffentlicht 25.09.2026 02:43:13
- Zuletzt bearbeitet 30.09.2026 17:23:08
In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) widget sequence data handling allows an authenticated attacker to execute arbitrary PHP code. To exploit this, a...
CVE-2026-78849
- EPSS 0.26%
- Veröffentlicht 04.09.2026 00:00:00
- Zuletzt bearbeitet 14.09.2026 14:17:09
Cross Site Scripting vulnerability in Netgate pfSense Plus software versions <= 26.03 pfSense CE software versions <= 2.8.1 allows a remote attacker to execute arbitrary code via the captive_portal_status.widget.php file
CVE-2026-38961
- EPSS 0.23%
- Veröffentlicht 04.09.2026 00:00:00
- Zuletzt bearbeitet 09.09.2026 20:17:22
Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense Plus (versions 26.03, 25.11.1) and pfSense CE (version 2.8.1) allows remote authenticated attackers to inject arbitrary JavaScript via malicious content in an RSS feed titl...
CVE-2026-56128
- EPSS 0.37%
- Veröffentlicht 03.09.2026 14:22:32
- Zuletzt bearbeitet 09.09.2026 20:41:07
pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Schedules: Edit privilege to inject arbitrary JavaScript via the descr parameter in /firewall_schedule_edit.php. The schedule description is stored without HTM...
CVE-2026-56127
- EPSS 0.37%
- Veröffentlicht 03.09.2026 14:21:35
- Zuletzt bearbeitet 09.09.2026 20:41:07
pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Rules: Edit privilege to inject arbitrary JavaScript via the descr parameter in /firewall_rules_edit.php. The firewall rule description is stored in the pfSens...
CVE-2026-56126
- EPSS 0.37%
- Veröffentlicht 03.09.2026 14:19:43
- Zuletzt bearbeitet 09.09.2026 20:41:07
pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Status: Monitoring privilege to inject arbitrary JavaScript via graph configuration parameters in /status_monitoring.php. Multiple POST parameters including graph-left, ...
CVE-2026-67189
- EPSS 0.53%
- Veröffentlicht 19.08.2026 19:18:50
- Zuletzt bearbeitet 23.09.2026 18:14:58
pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature, where PTR records returned by reverse DNS lookups are incorporated without sanitization into AJAX re...
CVE-2025-69691
- EPSS 0.53%
- Veröffentlicht 08.05.2026 00:00:00
- Zuletzt bearbeitet 12.05.2026 20:39:48
Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only available to admins and they are intentionally allowed to execute PHP code.
CVE-2025-69690
- EPSS 0.63%
- Veröffentlicht 08.05.2026 00:00:00
- Zuletzt bearbeitet 12.05.2026 13:45:34
Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_reboot_commands property. NOTE: the Supplier disputes this because this installer is only available to ad...
CVE-2025-34178
- EPSS 3.64%
- Veröffentlicht 09.09.2025 20:23:44
- Zuletzt bearbeitet 14.07.2026 23:17:22
In pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored cross-site scripting. The attacker must be authent...