ISOMAN

Filtered CVEs

pfSense-CE-2.7.0-RELEASE-amd64.iso.gz CVEs

CVEs linked through pfSense CE 2.7.0 amd64 ce iso.

Release Context

  1. pfSense CE · 2.7.0 amd64 ce iso

7 CVEs

  1. CVE-2026-67189
    MEDIUM · CVSS 5.3 ·

    pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature, where PTR records returned by reverse DNS lookups are incorporated without sanitization into AJAX responses and rendered as HTML through a DOM sink in the administrator interface. An attacker who controls a PTR record and generates sufficient traffic to appear as a top talker can execute arbitrary JavaScript in an administrator's browser, gaining access to the authenticated session context and same-origin access to the firewall management interface, enabling account creation and arbitrary OS command execution.

  2. CVE-2023-48123
    HIGH · CVSS 8.8 ·

    An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the packet_capture.php file.

  3. CVE-2023-42326
    HIGH · CVSS 8.8 ·

    An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components.

  4. CVE-2023-42327
    MEDIUM · CVSS 5.4 ·

    Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getserviceproviders.php page.

  5. CVE-2023-42325
    MEDIUM · CVSS 5.4 ·

    Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the status_logs_filter_dynamic.php page.

  6. CVE-2023-27253
    HIGH · CVSS 8.8 ·

    A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml.

  7. CVE-2022-29273
    MEDIUM · CVSS 6.1 ·

    pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.