Impact
The vulnerability is a classic Cross‑Site Scripting (XSS) flaw in the RSS Widget of Netgate pfSense. Remote attackers who are authenticated can supply malicious content in an RSS feed title. Because the widget does not sanitize the title before rendering, the injected JavaScript runs in the browser of any authenticated user who views the dashboard. This permits an attacker to execute arbitrary client‑side code, potentially hijacking user sessions, exfiltrating sensitive information, or modifying the dashboard interface.
Affected Systems
The affected systems are Netgate pfSense Plus versions 26.03 and 25.11.1, and Netgate pfSense Community Edition version 2.8.1. These are the only product versions explicitly mentioned in the advisory. Users running earlier or later releases are not indicated as vulnerable.
Risk and Exploitability
Because this issue requires an attacker to have authenticated access, the attack vector is a remote authenticated user that can influence the RSS feed content. The lack of sanitization allows arbitrary script injection. The advisory states an EPSS score of < 1%, and the CVSS score is 5.4, which indicates moderate impact. The vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation has not yet been observed. The risk remains moderate for any organization that uses the mentioned pfSense versions with the RSS widget enabled on a dashboard visible to multiple authenticated users.
OpenCVE Enrichment