MEDIUM
OPNsense 19.1 Reflected XSS via proxy endpoint
Published Feb 15, 2026
5.1
MEDIUMCVSS 4.0
EPSS 0.39%
Description
OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted payloads through the ignoreLogACL parameter. Attackers can send POST requests to the proxy endpoint with JavaScript code in the ignoreLogACL parameter to execute arbitrary scripts in users' browsers.
Affected products
-
- Version 19.1StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
OPNsense 19.1.1 released
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-19418 Advisory
- https://forum.opnsense.org/index.php?topic=11469.0 patchRelease Notes
- https://opnsense.org product
- https://www.exploit-db.com/exploits/46351 exploitThird Party Advisory
- https://www.vulncheck.com/advisories/opnsense-reflected-xss-via-proxy-endpoint third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-19418 | Advisory | |
| https://forum.opnsense.org/index.php?topic=11469.0 | patchRelease Notes | |
| https://opnsense.org | product | |
| https://www.exploit-db.com/exploits/46351 | exploitThird Party Advisory | |
| https://www.vulncheck.com/advisories/opnsense-reflected-xss-via-proxy-endpoint | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Feb 15, 2026
Updated May 24, 2026
Reserved Feb 15, 2026
Link CVE-2019-25376
CISA Vulnrichment
Updated Feb 17, 2026
ENISA EUVD
EUVD-2019-19418 Assigner VulnCheck
Published Feb 15, 2026
Updated May 24, 2026
Exploited since n/a
Link EUVD-2019-19418