Skip to content
VulniPulse

Netgate pfSense Security Advisories & CVEs

30 advisories tracked · Netgate Security Advisories + NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor pfSense CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your pfSense device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in pfSense's recent advisories.

Official source

Netgate Security Advisories + NVD

Netgate maintains a dedicated Security Advisory index for pfSense (docs.netgate.com/advisories), but pfSense CVEs are assigned by MITRE and third-party researchers rather than a Netgate CNA — so VulniPulse ingests them from NVD (keyword-filtered to pfSense, dropped unless a pfSense/Netgate product is named) and links back to the Netgate advisory or pfSense reference. Covers pfSense CE (Community Edition) and pfSense Plus — a firewall/router at the network edge where a bug is directly internet-exposed.

Latest pfSense advisories

Medium5.4pfSense

Medium [CVE-2020-19201] Stored Cross-Site Scripting (XSS) vulnerability was found in status_filter_reload.php, a page in the pfSense software WebGUI…

A Stored Cross-Site Scripting (XSS) vulnerability was found in status_filter_reload.php, a page in the pfSense software WebGUI, on Netgate pfSense version 2.4.4-p2 and earlier. The page did not encode output from the filter reload process, and a stored XSS was possible via the descr (description) parameter on NAT rules.

CVE-2020-19201
Unclassified
Jul 12, 2021
Medium5.4pfSense

Medium [CVE-2020-26693] stored cross-site scripting (XSS) vulnerability was discovered in pfSense 2.4.5-p1 which

A stored cross-site scripting (XSS) vulnerability was discovered in pfSense 2.4.5-p1 which allows an authenticated attacker to execute arbitrary web scripts via exploitation of the load_balancer_monitor.php function.

CVE-2020-26693
Unclassified
Jun 1, 2021
Medium6.1pfSense

Medium [CVE-2021-27933] pfSense: pfSense 2.5.0 allows XSS via the services_wol_edit.php Description field.

pfSense 2.5.0 allows XSS via the services_wol_edit.php Description field.

CVE-2021-27933
Unclassified
Apr 28, 2021
Medium5.4pfSense

Medium [CVE-2020-11457] pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI

pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI via the descr parameter (aka full name) of a user.

CVE-2020-11457
Unclassified
Apr 1, 2020
Medium6.1pfSense

Medium [CVE-2019-18667] /usr/local/www/freeradius_view_config.php in the freeradius3 package before 0.15.7_3 for pfSense on FreeBSD

/usr/local/www/freeradius_view_config.php in the freeradius3 package before 0.15.7_3 for pfSense on FreeBSD allows a user with an XSS payload as password or username to execute arbitrary javascript code on a victim browser.

CVE-2019-18667
Unclassified
Nov 2, 2019
Medium6.1pfSense

Medium [CVE-2019-16914] pfSense: XSS issue was discovered in pfSense through 2.4.4-p3.

An XSS issue was discovered in pfSense through 2.4.4-p3. In services_captiveportal_mac.php, the username and delmac parameters are displayed without sanitization.

CVE-2019-16914
Unclassified
Sep 26, 2019
Medium6.1pfSense

Medium [CVE-2019-12949] In pfSense 2.4.4-p2 and 2.4.4-p3, if it is possible to trick an authenticated administrator into clicking on a button on a…

In pfSense 2.4.4-p2 and 2.4.4-p3, if it is possible to trick an authenticated administrator into clicking on a button on a phishing page, an attacker can leverage XSS to upload arbitrary executable code, via diag_command.php and rrd_fetch_json.php (timePeriod parameter), to a server. Then, the remote attacker can run any command with root privileges on that server.

CVE-2019-12949
Unclassified
Jun 25, 2019
Medium6.1pfSense

Medium [CVE-2019-12584] Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an XSS issue in apcupsd_status.php

Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an XSS issue in apcupsd_status.php.

CVE-2019-12584
Unclassified
Jun 3, 2019
Medium6.1pfSense

Medium [CVE-2019-12347] In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field

In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accountkeys_edit.php action. The vulnerability occurs due to input validation errors.

CVE-2019-12347
Unclassified
May 29, 2019
Medium6.1pfSense

Medium [CVE-2019-8953] The HAProxy package before 0.59_16 for pfSense has XSS

The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_listeners.php and haproxy_listeners_edit.php.

CVE-2019-8953
Unclassified
Feb 20, 2019

← All vendors