CVE-2025-34178
- EPSS 0.08%
- Published 09.09.2025 20:23:44
- Last modified 17.09.2025 18:15:44
In pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored cross-site scripting. The attacker must be authent...
CVE-2025-34177
- EPSS 0.08%
- Published 09.09.2025 20:19:09
- Last modified 17.09.2025 18:15:44
In pfSense CE /suricata/suricata_flow_stream.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored cross-site scripting. The attacker must be authent...
CVE-2025-34176
- EPSS 0.32%
- Published 09.09.2025 20:14:37
- Last modified 17.09.2025 18:15:44
In pfSense CE /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related strings/characters. This value is directly used in a file existence check operation. While the contents of the file ...
CVE-2025-34175
- EPSS 0.12%
- Published 09.09.2025 20:09:50
- Last modified 17.09.2025 18:15:44
In pfSense CE /usr/local/www/suricata/suricata_filecheck.php, the value of the filehash parameter is directly displayed without sanitizing for HTML-related characters/strings. This can result in reflected cross-site scripting if the victim is authent...
CVE-2025-34174
- EPSS 0.08%
- Published 09.09.2025 20:02:05
- Last modified 17.09.2025 18:15:44
In pfSense CE /usr/local/www/status_traffic_totals.php, the value of the start-day parameter is not ensured to be a numeric value or sanitized of HTML-related characters/strings before being directly displayed in the input box. This value can be save...
CVE-2025-34173
- EPSS 0.32%
- Published 09.09.2025 19:59:14
- Last modified 17.09.2025 18:15:44
In pfSense CE /usr/local/www/snort/snort_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related characters/strings before being used to check if a file exists. While the contents of the file cannot be rea...
CVE-2025-34172
- EPSS 0.1%
- Published 09.09.2025 19:43:30
- Last modified 17.09.2025 18:15:43
In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent parameter is displayed after being read from HTTP GET requests. This can enable reflected cross-site scripting when the victim is authenticated.
CVE-2024-54780
- EPSS 0.72%
- Published 14.05.2025 00:00:00
- Last modified 13.06.2025 13:03:51
Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitization of user-supplied input to the OpenVPN management interface. An authenticated attacke...
CVE-2024-54779
- EPSS 0.01%
- Published 14.05.2025 00:00:00
- Last modified 23.06.2025 14:51:38
Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php.
CVE-2024-57273
- EPSS 0.13%
- Published 14.05.2025 00:00:00
- Last modified 23.06.2025 14:50:34
Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross-site scripting (XSS) in the Automatic Configuration Backup (ACB) service, allowing remote attackers to execute arbitrary JavaScript, delete backups,...