Products: 12
    Vulnerabilities: 76
    Known Exploited: 0
    7
    Critical Level Threats
    21
    High Level Threats
    47
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-38961

    Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense Plus (versions 26.03, 25.11.1) and pfSense CE (version 2.8.1) allows remote authenticated attackers to inject arbitrary JavaScript via malicious content in an RSS feed title. The injected script executes in the browser of any authenticated user who views the dashboard, due to insufficient sanitization of feed title data before rendering in the widget.

    Last Modified: Sep 10, 2026
    Published: Sep 04, 2026

    CVE-2026-78849

    Cross‑Site Scripting in pfSense Captive Portal Status Widget Enables Remote Code Execution

    Last Modified: Sep 04, 2026
    Published: Sep 04, 2026

    CVE-2026-56128

    pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via firewall_schedule_edit.php

    Last Modified: Sep 03, 2026
    Published: Sep 03, 2026

    CVE-2026-56127

    pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via firewall_rules_edit.php

    Last Modified: Sep 03, 2026
    Published: Sep 03, 2026

    CVE-2026-56126

    pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via status_monitoring.php

    Last Modified: Sep 05, 2026
    Published: Sep 03, 2026
    Items Per Page