Cross Site Scripting Vulnerability in Netgate pfSense Software
CVE-2026-78849
5.4MEDIUM
What is CVE-2026-78849?
A Cross Site Scripting (XSS) vulnerability exists in the Netgate pfSense Plus software and pfSense Community Edition, specifically in the 'captive_portal_status.widget.php' file. This issue allows remote attackers to execute arbitrary code, potentially compromising system integrity and security by injecting malicious scripts into web pages. The vulnerability affects versions of pfSense Plus up to 26.03 and pfSense CE up to 2.8.1, posing a significant risk for users who have not secured their systems against this threat.
