CVE-2026-38961: XSS
Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense Plus (versions 26.03, 25.11.1) and pfSense CE (version 2.8.1) allows remote authenticated attackers to inject arbitrary JavaScript via malicious content in an RSS feed title. The injected script executes in the browser of any authenticated user who views the dashboard, due to insufficient sanitization of feed title data before rendering in the widget.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Administrators or other authenticated users who view a pfSense dashboard containing the RSS Widget are exposed. The issue affects pfSense Plus 26.03 and 25.11.1, and pfSense CE 2.8.1.
What does an attacker need to exploit it?
An attacker must be remotely authenticated and must be able to cause malicious JavaScript to be included in an RSS feed title consumed by the RSS Widget. The payload executes when another authenticated user views the dashboard.
Are unauthenticated users affected simply by visiting the dashboard?
No. The described attack requires an authenticated attacker and execution occurs in the browser of an authenticated user viewing the dashboard.