CVE-2026-97730
- EPSS 1.03%
- Veröffentlicht 25.09.2026 02:43:13
- Zuletzt bearbeitet 30.09.2026 17:23:08
In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) widget sequence data handling allows an authenticated attacker to execute arbitrary PHP code. To exploit this, a...
CVE-2026-78849
- EPSS 0.26%
- Veröffentlicht 04.09.2026 00:00:00
- Zuletzt bearbeitet 14.09.2026 14:17:09
Cross Site Scripting vulnerability in Netgate pfSense Plus software versions <= 26.03 pfSense CE software versions <= 2.8.1 allows a remote attacker to execute arbitrary code via the captive_portal_status.widget.php file
CVE-2026-38961
- EPSS 0.23%
- Veröffentlicht 04.09.2026 00:00:00
- Zuletzt bearbeitet 09.09.2026 20:17:22
Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense Plus (versions 26.03, 25.11.1) and pfSense CE (version 2.8.1) allows remote authenticated attackers to inject arbitrary JavaScript via malicious content in an RSS feed titl...
CVE-2026-56128
- EPSS 0.37%
- Veröffentlicht 03.09.2026 14:22:32
- Zuletzt bearbeitet 09.09.2026 20:41:07
pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Schedules: Edit privilege to inject arbitrary JavaScript via the descr parameter in /firewall_schedule_edit.php. The schedule description is stored without HTM...
CVE-2026-56127
- EPSS 0.37%
- Veröffentlicht 03.09.2026 14:21:35
- Zuletzt bearbeitet 09.09.2026 20:41:07
pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Rules: Edit privilege to inject arbitrary JavaScript via the descr parameter in /firewall_rules_edit.php. The firewall rule description is stored in the pfSens...
CVE-2026-56126
- EPSS 0.37%
- Veröffentlicht 03.09.2026 14:19:43
- Zuletzt bearbeitet 09.09.2026 20:41:07
pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Status: Monitoring privilege to inject arbitrary JavaScript via graph configuration parameters in /status_monitoring.php. Multiple POST parameters including graph-left, ...
CVE-2026-67189
- EPSS 0.53%
- Veröffentlicht 19.08.2026 19:18:50
- Zuletzt bearbeitet 23.09.2026 18:14:58
pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature, where PTR records returned by reverse DNS lookups are incorporated without sanitization into AJAX re...
CVE-2024-54779
- EPSS 8.28%
- Veröffentlicht 14.05.2025 00:00:00
- Zuletzt bearbeitet 23.06.2025 14:51:38
Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php.
CVE-2024-57273
- EPSS 1.24%
- Veröffentlicht 14.05.2025 00:00:00
- Zuletzt bearbeitet 05.07.2026 01:21:16
Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross-site scripting (XSS) in the Automatic Configuration Backup (ACB) service, allowing remote attackers to execute arbitrary JavaScript, delete backups,...
CVE-2024-54780
- EPSS 12.15%
- Veröffentlicht 14.05.2025 00:00:00
- Zuletzt bearbeitet 13.06.2025 13:03:51
Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitization of user-supplied input to the OpenVPN management interface. An authenticated attacke...