Netgate / Pfsense Plus
10 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-97730 | In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) widget sequence data… | HIGH | 8.5 | Sep 25, 2026 |
| CVE-2026-56128 | pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via firewall_schedule_edit.php | MEDIUM | 5.1 | Sep 3, 2026 |
| CVE-2026-56127 | pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via firewall_rules_edit.php | MEDIUM | 5.1 | Sep 3, 2026 |
| CVE-2026-56126 | pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via status_monitoring.php | MEDIUM | 5.1 | Sep 3, 2026 |
| CVE-2026-67189 | pfSense Plus/CE Stored XSS via Traffic Graphs PTR Record | MEDIUM | 5.3 | Aug 19, 2026 |
| CVE-2024-57273 | Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross-site scripting (XSS) in the Automatic Configuration Backu… | MEDIUM | 5.4 | May 14, 2025 |
| CVE-2024-54780 | Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper saniti… | HIGH | 8.8 | May 14, 2025 |
| CVE-2024-54779 | Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php. | MEDIUM | 5.4 | May 14, 2025 |
| CVE-2023-48795 | ssh: Prefix truncation attack on Binary Packet Protocol (BPP) | MEDIUM | 5.9 | Dec 18, 2023 |
| CVE-2023-48123 | An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the pa… | HIGH | 8.8 | Dec 6, 2023 |
| CVE-2023-42326 | An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_… | HIGH | 8.8 | Nov 14, 2023 |
| CVE-2023-27100 | Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 al… | CRITICAL | 9.8 | Mar 22, 2023 |
| CVE-2022-26019 | Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 2… | HIGH | 8.8 | Mar 31, 2022 |
| CVE-2022-24299 | Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to… | HIGH | 8.8 | Mar 31, 2022 |
| CVE-2021-20729 | Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and pfSense Plus software versions 21.05 and… | MEDIUM | 6.1 | Mar 31, 2022 |
Showing 1 to 10 of 10 CVEs