VulnSea

pfsense has 6 CVEs on record. The median CVSS is 5.4 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-79 (4).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.4
Publish → KEV
Last 90 days
0 prev 0

Weakness classes

Products

  • pfsense 6
6
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

pfsense vulnerabilities

CVEs affecting pfsense, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2025-34178Medium· 5.4
1y ago

In pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed

In pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored cross-site scripting. The attacker mu…

Sunlitpfsense · pfsenseEPSS 3.7%via NVD
CVE-2025-34177Medium· 5.4
1y ago

In pfSense CE /suricata/suricata_flow_stream.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed

In pfSense CE /suricata/suricata_flow_stream.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored cross-site scripting. The attacker mu…

Sunlitpfsense · pfsenseEPSS 0.86%via NVD
CVE-2025-34176Medium· 4.3
1y ago

In pfSense CE /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related strings/characters

In pfSense CE /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related strings/characters. This value is directly used in a file existence check operation. While the contents…

Sunlitpfsense · pfsenseEPSS 15%via NVD
CVE-2025-34175Medium· 6.1
1y ago

In pfSense CE /usr/local/www/suricata/suricata_filecheck.php, the value of the filehash parameter is directly displayed without sanitizing for HTML-related characters/strings

In pfSense CE /usr/local/www/suricata/suricata_filecheck.php, the value of the filehash parameter is directly displayed without sanitizing for HTML-related characters/strings. This can result in reflected cross-site scripting if the vict…

Sunlitpfsense · pfsenseEPSS 15%via NVD
CVE-2025-34173Medium· 4.3
1y ago

In pfSense CE /usr/local/www/snort/snort_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related characters/strings before being used to check if a file exists

In pfSense CE /usr/local/www/snort/snort_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related characters/strings before being used to check if a file exists. While the contents of the file …

Sunlitpfsense · pfsenseEPSS 0.90%via NVD
CVE-2025-34172Medium· 6.1
1y ago

In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent parameter is displayed after being read from HTTP GET requests

In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent parameter is displayed after being read from HTTP GET requests. This can enable reflected cross-site scripting when the victim is authenticated.

Sunlitpfsense · pfsenseEPSS 1.0%via NVD
pfsense vulnerabilities (CVEs) · VulnSea