CVE-2026-38961

Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense Plus (versions 26.03, 25.11.1) and pfSense CE (version 2.8.1) allows remote authenticated attackers to inject arbitrary JavaScript via malicious content in an RSS feed title. The injected script executes in the browser of any authenticated user who views the dashboard, due to insufficient sanitization of feed title data before rendering in the widget.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-04 17:16

Updated : 2026-09-09 20:17


NVD link : CVE-2026-38961

Mitre link : CVE-2026-38961

CVE.ORG link : CVE-2026-38961


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')