Products: 12
Vulnerabilities: 76
Known Exploited: 0
7
Critical Level Threats
21
High Level Threats
47
Medium Level Threats
0
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2026-38961
Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense Plus (versions 26.03, 25.11.1) and pfSense CE (version 2.8.1) allows remote authenticated attackers to inject arbitrary JavaScript via malicious content in an RSS feed title. The injected script executes in the browser of any authenticated user who views the dashboard, due to insufficient sanitization of feed title data before rendering in the widget.
Last Modified: Sep 10, 2026
Published: Sep 04, 2026
CVE-2026-78849
Cross‑Site Scripting in pfSense Captive Portal Status Widget Enables Remote Code Execution
Last Modified: Sep 04, 2026
Published: Sep 04, 2026
CVE-2026-56128
pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via firewall_schedule_edit.php
Last Modified: Sep 03, 2026
Published: Sep 03, 2026
CVE-2026-56127
pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via firewall_rules_edit.php
Last Modified: Sep 03, 2026
Published: Sep 03, 2026
CVE-2026-56126
pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via status_monitoring.php
Last Modified: Sep 05, 2026
Published: Sep 03, 2026
Items Per Page
