End of life: 1/28/2025, Latest version: 24.7.12
End of life: 1/28/2025, Latest version: 24.7.12
End of life: 7/25/2024, Latest version: 24.1.10
End of life: 7/25/2024, Latest version: 24.1.10
DECISO OPNsense 23.1 does not impose rate limits for authentication, allowing attackers to perform a brute-force attack to bypass authentication.
OPNsense before 23.7.5 allows XSS via the index.php sequence parameter to the Lobby Dashboard.
OPNsense before 23.7.5 allows XSS via the index.php columncount parameter to the Lobby Dashboard.
A cross-site scripting (XSS) vulnerability in the act parameter of systemcertmanager.php in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
A directory traversal vulnerability in the Captive Portal templates of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary system commands as root via a crafted ZIP archive.
A command injection vulnerability in the component diagbackup.php of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary commands via a crafted backup configuration file.
Insecure permissions exist for configd.socket in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2.
/ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows XSS via openAction in app/controllers/OPNsense/Cron/ItemController.php.
A command injection vulnerability in the component /api/cron/settings/setJob/ of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary system commands.
A Cross-Site Request Forgery (CSRF) in the System Halt API (/system/halt) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
The Crash Reporter (crashreporter.php) component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 mishandles input sanitization.
A reflected cross-site scripting (XSS) vulnerability in the component /ui/diagnostics/log/core/ of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to inject arbitrary JavaScript via the URL path.
An open redirect in the Login page of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to redirect a victim user to an arbitrary web site via a crafted URL.
End of life: 1/26/2024, Latest version: 23.7.12
End of life: 1/26/2024, Latest version: 23.7.12
End of life: 7/28/2023, Latest version: 23.1.11
End of life: 7/28/2023, Latest version: 23.1.11
End of life: 1/25/2023, Latest version: 22.7.11
End of life: 1/25/2023, Latest version: 22.7.11
End of life: 7/25/2022, Latest version: 22.1.10
End of life: 7/25/2022, Latest version: 22.1.10
A Cross-site scripting (XSS) vulnerability was discovered in OPNsense before 21.7.4 via the LDAP attribute return in the authentication tester.
End of life: 1/25/2022, Latest version: 21.7.8
End of life: 1/25/2022, Latest version: 21.7.8
An open redirect issue was discovered in OPNsense through 20.1.5. The redirect parameter "url" in login page was not filtered and can redirect user to any website.
End of life: 7/23/2021, Latest version: 21.1.9