Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense Plus (versions 26.03, 25.11.1) and pfSense CE (version 2.8.1) allows remote authenticated attackers to inject arbitrary JavaScript via malicious content in an RSS feed title. The injected script executes in the browser of any authenticated user who views the dashboard, due to insufficient sanitization of feed title data before rendering in the widget.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-04 17:16
Updated : 2026-09-09 20:17
NVD link : CVE-2026-38961
Mitre link : CVE-2026-38961
CVE.ORG link : CVE-2026-38961
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
