Opnsense Vulnerabilities

Comprehensive security vulnerability database for Opnsense products

Last updated: Feb 15, 2026
Total CVEs

10

Critical

0

With Exploits

8

Last 30 Days

0

Severity Distribution

Critical0
0%
High0
0%
Medium10
100%
Low0
0%
DescriptionVendor / ProductExploit Status
CVE-2019-253774.8

This vulnerability allows attackers to run malicious JavaScript in the web browser of users who are logged into the OPNsense system, potentially stealing their session cookies or other sensitive information. It requires the attacker to send specially crafted requests to a specific part of the system while the user is authenticated.

opnsenseopnsense
Theoretical
about 2 months agoFeb 15, 2026
CVE-2019-253765.1

This vulnerability allows attackers to run malicious scripts in the browsers of users visiting the OPNsense web interface, potentially stealing sensitive information or performing actions on behalf of the user. To exploit this, attackers need to send specially crafted requests to the system without needing to log in.

opnsenseopnsense
Theoretical
about 2 months agoFeb 15, 2026
CVE-2019-253755.1

This vulnerability allows attackers to inject harmful scripts into users' browsers by sending specially crafted requests to the mailserver parameter on the OPNsense interface. It requires no authentication, meaning anyone can exploit it if they know how to send the right type of request.

opnsenseopnsense
Exploit Available
about 2 months agoFeb 15, 2026
CVE-2019-253745.1

This vulnerability allows attackers to inject harmful scripts into users' browsers by exploiting a specific parameter in OPNsense's VPN settings. To succeed, the attacker needs to send specially crafted requests that include malicious JavaScript, which can then execute unwanted actions on the user's device when they access the affected page.

opnsenseopnsense
Exploit Available
about 2 months agoFeb 15, 2026
CVE-2019-253735.1

This vulnerability allows an attacker to inject harmful scripts that can run in the web browsers of other users who view certain firewall rule pages. To exploit this, the attacker must be authenticated and can send specially crafted data through a specific form field.

opnsenseopnsense
Exploit Available
about 2 months agoFeb 15, 2026
CVE-2019-253725.1

An attacker can inject harmful scripts into a user's browser session, allowing them to execute arbitrary JavaScript when the user visits a specific page on the OPNsense system. This vulnerability can be exploited by sending specially crafted requests without needing to log in, making it easier for attackers to target unsuspecting users.

opnsenseopnsense
Exploit Available
about 2 months agoFeb 15, 2026
CVE-2019-253715.1

An attacker can inject harmful scripts into users' browsers by sending specially crafted requests to a specific page in OPNsense, allowing them to execute arbitrary JavaScript. This vulnerability can be exploited without needing to log in, as long as the attacker can trick users into visiting the affected page.

opnsenseopnsense
Exploit Available
about 2 months agoFeb 15, 2026
CVE-2019-253705.1

This vulnerability allows attackers to run malicious JavaScript in the web browsers of users who visit a compromised page, potentially stealing sensitive information or taking control of their sessions. It can be exploited by sending specially crafted data through specific parameters in a POST request to the OPNsense interface, meaning the attacker needs to trick users into interacting with a vulnerable page.

opnsenseopnsense
Exploit Available
about 2 months agoFeb 15, 2026
CVE-2019-253695.1

This vulnerability allows attackers to inject harmful scripts into the OPNsense web interface, which can then run automatically when an authenticated user visits the affected page. To exploit this, the attacker needs to send a specially crafted request with the malicious script while the user is logged in.

opnsenseopnsense
Exploit Available
about 2 months agoFeb 15, 2026
CVE-2019-253684.8

This vulnerability allows an attacker to run malicious scripts in the web browser of an authenticated administrator, potentially stealing sensitive information or taking control of the admin session. To exploit this, the attacker needs to send specially crafted requests to a specific part of the OPNsense system while the administrator is logged in.

opnsenseopnsense
Exploit Available
about 2 months agoFeb 15, 2026

About Opnsense Security

This page tracks all publicly disclosed security vulnerabilities (CVEs) affecting Opnsense products. Our database is updated in real-time from the National Vulnerability Database (NVD) and enriched with exploit information from GitHub and other security research sources.

Each CVE listing includes CVSS severity scores, exploit availability status, AI-powered vulnerability summaries, and links to official patches and security advisories.