Opnsense Vulnerabilities
Comprehensive security vulnerability database for Opnsense products
10
0
8
0
Severity Distribution
| Description | Vendor / Product | Exploit Status | |||
|---|---|---|---|---|---|
| CVE-2019-25377 | 4.8 | This vulnerability allows attackers to run malicious JavaScript in the web browser of users who are logged into the OPNsense system, potentially stealing their session cookies or other sensitive information. It requires the attacker to send specially crafted requests to a specific part of the system while the user is authenticated. | opnsenseopnsense | Theoretical | about 2 months agoFeb 15, 2026 |
| CVE-2019-25376 | 5.1 | This vulnerability allows attackers to run malicious scripts in the browsers of users visiting the OPNsense web interface, potentially stealing sensitive information or performing actions on behalf of the user. To exploit this, attackers need to send specially crafted requests to the system without needing to log in. | opnsenseopnsense | Theoretical | about 2 months agoFeb 15, 2026 |
| CVE-2019-25375 | 5.1 | This vulnerability allows attackers to inject harmful scripts into users' browsers by sending specially crafted requests to the mailserver parameter on the OPNsense interface. It requires no authentication, meaning anyone can exploit it if they know how to send the right type of request. | opnsenseopnsense | Exploit Available | about 2 months agoFeb 15, 2026 |
| CVE-2019-25374 | 5.1 | This vulnerability allows attackers to inject harmful scripts into users' browsers by exploiting a specific parameter in OPNsense's VPN settings. To succeed, the attacker needs to send specially crafted requests that include malicious JavaScript, which can then execute unwanted actions on the user's device when they access the affected page. | opnsenseopnsense | Exploit Available | about 2 months agoFeb 15, 2026 |
| CVE-2019-25373 | 5.1 | This vulnerability allows an attacker to inject harmful scripts that can run in the web browsers of other users who view certain firewall rule pages. To exploit this, the attacker must be authenticated and can send specially crafted data through a specific form field. | opnsenseopnsense | Exploit Available | about 2 months agoFeb 15, 2026 |
| CVE-2019-25372 | 5.1 | An attacker can inject harmful scripts into a user's browser session, allowing them to execute arbitrary JavaScript when the user visits a specific page on the OPNsense system. This vulnerability can be exploited by sending specially crafted requests without needing to log in, making it easier for attackers to target unsuspecting users. | opnsenseopnsense | Exploit Available | about 2 months agoFeb 15, 2026 |
| CVE-2019-25371 | 5.1 | An attacker can inject harmful scripts into users' browsers by sending specially crafted requests to a specific page in OPNsense, allowing them to execute arbitrary JavaScript. This vulnerability can be exploited without needing to log in, as long as the attacker can trick users into visiting the affected page. | opnsenseopnsense | Exploit Available | about 2 months agoFeb 15, 2026 |
| CVE-2019-25370 | 5.1 | This vulnerability allows attackers to run malicious JavaScript in the web browsers of users who visit a compromised page, potentially stealing sensitive information or taking control of their sessions. It can be exploited by sending specially crafted data through specific parameters in a POST request to the OPNsense interface, meaning the attacker needs to trick users into interacting with a vulnerable page. | opnsenseopnsense | Exploit Available | about 2 months agoFeb 15, 2026 |
| CVE-2019-25369 | 5.1 | This vulnerability allows attackers to inject harmful scripts into the OPNsense web interface, which can then run automatically when an authenticated user visits the affected page. To exploit this, the attacker needs to send a specially crafted request with the malicious script while the user is logged in. | opnsenseopnsense | Exploit Available | about 2 months agoFeb 15, 2026 |
| CVE-2019-25368 | 4.8 | This vulnerability allows an attacker to run malicious scripts in the web browser of an authenticated administrator, potentially stealing sensitive information or taking control of the admin session. To exploit this, the attacker needs to send specially crafted requests to a specific part of the OPNsense system while the administrator is logged in. | opnsenseopnsense | Exploit Available | about 2 months agoFeb 15, 2026 |
About Opnsense Security
This page tracks all publicly disclosed security vulnerabilities (CVEs) affecting Opnsense products. Our database is updated in real-time from the National Vulnerability Database (NVD) and enriched with exploit information from GitHub and other security research sources.
Each CVE listing includes CVSS severity scores, exploit availability status, AI-powered vulnerability summaries, and links to official patches and security advisories.