CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “opnsense”

32 vulnerabilities found for “opnsense”

Page 1 of 2

CVE-2019-25368
MEDIUM5.4

OPNsense 19.1 contains multiple cross-site scripting vulnerabilities in the diag_backup.php endpoint that allow attackers to inject malicious scripts through multiple parameters including GDrive_GDriveEmail, GDrive_GDriveFolderID, GDrive_GDriveBackupCount, Nextcloud_url, Nextcloud_user, Nextcloud_password, Nextcloud_password_encryption, and Nextcloud_backupdir. Attackers can submit POST requests with script payloads in these parameters to execute arbitrary JavaScript in the context of authenticated administrator sessions.

opnsense / opnsense
Network
Published Feb 15, 2026
Page 1 of 2
CVE-2025-50989
CRITICAL9.1

OPNsense before 25.1.8 contains an authenticated command injection vulnerability in its Bridge Interface Edit endpoint (interfaces_bridge_edit.php). The span POST parameter is concatenated into a system-level command without proper sanitization or escaping, allowing an administrator to inject arbitrary shell operators and payloads. Successful exploitation results in remote code execution with the privileges of the web service (typically root), potentially leading to full system compromise or lateral movement. This vulnerability arises from inadequate input validation and improper handling of user-supplied data in backend command invocations.

opnsense / opnsense
Network
Published Aug 27, 2025
CVE-2023-27152
CRITICAL9.8

DECISO OPNsense 23.1 does not impose rate limits for authentication, allowing attackers to perform a brute-force attack to bypass authentication.

opnsense / opnsense
Network
Published Oct 23, 2023
CVE-2023-44275
MEDIUM5.4

OPNsense before 23.7.5 allows XSS via the index.php column_count parameter to the Lobby Dashboard.

opnsense / opnsense
Network
Published Sep 28, 2023
CVE-2023-44276
MEDIUM5.4

OPNsense before 23.7.5 allows XSS via the index.php sequence parameter to the Lobby Dashboard.

opnsense / opnsense
Network
Published Sep 28, 2023
CVE-2023-38997
HIGH7.2

A directory traversal vulnerability in the Captive Portal templates of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary system commands as root via a crafted ZIP archive.

opnsense / opnsense
Network
Published Aug 9, 2023
CVE-2023-39008
CRITICAL9.8

A command injection vulnerability in the component /api/cron/settings/setJob/ of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary system commands.

opnsense / opnsense
Network
Published Aug 9, 2023
CVE-2023-38999
MEDIUM6.5

A Cross-Site Request Forgery (CSRF) in the System Halt API (/system/halt) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to cause a Denial of Service (DoS) via a crafted GET request.

opnsense / opnsense
Network
Published Aug 9, 2023
CVE-2023-39007
CRITICAL9.6

/ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows XSS via openAction in app/controllers/OPNsense/Cron/ItemController.php.

opnsense / opnsense
Network
Published Aug 9, 2023
CVE-2023-39002
MEDIUM6.1

A cross-site scripting (XSS) vulnerability in the act parameter of system_certmanager.php in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

opnsense / opnsense
Network
Published Aug 9, 2023
CVE-2023-39001
CRITICAL9.8

A command injection vulnerability in the component diag_backup.php of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary commands via a crafted backup configuration file.

opnsense / opnsense
Network
Published Aug 9, 2023
CVE-2023-39004
CRITICAL9.8

Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attackers to access sensitive information (e.g., hashed root password) which could lead to privilege escalation.

opnsense / opnsense
Network
Published Aug 9, 2023
CVE-2023-39005
HIGH7.5

Insecure permissions exist for configd.socket in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2.

opnsense / opnsense
Network
Published Aug 9, 2023
CVE-2023-39003
HIGH7.5

OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 was discovered to contain insecure permissions in the directory /tmp.

opnsense / opnsense
Network
Published Aug 9, 2023
CVE-2023-39006
MEDIUM5.4

The Crash Reporter (crash_reporter.php) component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 mishandles input sanitization.

opnsense / opnsense
Network
Published Aug 9, 2023
CVE-2023-39000
MEDIUM6.1

A reflected cross-site scripting (XSS) vulnerability in the component /ui/diagnostics/log/core/ of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to inject arbitrary JavaScript via the URL path.

opnsense / opnsense
Network
Published Aug 9, 2023
CVE-2023-38998
MEDIUM6.1

An open redirect in the Login page of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to redirect a victim user to an arbitrary web site via a crafted URL.

opnsense / opnsense
Network
Published Aug 9, 2023
CVE-2021-42770
MEDIUM6.1

A Cross-site scripting (XSS) vulnerability was discovered in OPNsense before 21.7.4 via the LDAP attribute return in the authentication tester.

opnsense / opnsense+1
Network
Published Nov 8, 2021
CVE-2020-23015
MEDIUM6.1

An open redirect issue was discovered in OPNsense through 20.1.5. The redirect parameter "url" in login page was not filtered and can redirect user to any website.

opnsense / opnsense
Network
Published May 3, 2021
CVE-2017-1000479
HIGH8.8

pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrary code, because the error detection occurs before an X-Frame-Options header is set. This is fixed in 2.4.2-RELEASE. OPNsense, a 2015 fork of pfSense, was not vulnerable since version 16.1.16 released on June 06, 2016. The unprotected web form was removed from the code during an internal security audit under "possibly insecure" suspicions.

netgate / pfsense+1
Network
Published Jan 3, 2018