CVE-2026-38961 Details
Description
Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense Plus (versions 26.03, 25.11.1) and pfSense CE (version 2.8.1) allows remote authenticated attackers to inject arbitrary JavaScript via malicious content in an RSS feed title. The injected script executes in the browser of any authenticated user who views the dashboard, due to insufficient sanitization of feed title data before rendering in the widget.
A Cross-Site Scripting (XSS) vulnerability has been identified in the RSS Widget of Netgate pfSense Plus (versions 26.03, 25.11.1) and pfSense CE (version 2.8.1). This vulnerability allows remote authenticated attackers to inject arbitrary JavaScript by embedding malicious content in an RSS feed title. The injected script executes in the browser of any authenticated user who views the dashboard, due to inadequate sanitization of feed title data before it is displayed in the widget.
Users can upgrade to pfSense Plus version 26.07 or later, or pfSense CE versions after 2.8.1 when available. This upgrade can be performed through the web interface or from the console. Users on pfSense Plus versions 26.03 or 25.11.1, and pfSense CE version 2.8.1 can apply the fix from the recommended patches list in the System Patches package after updating the package. Instructions for applying system patches are available in the pfSense documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 4, 2026CISA-ADP
Assessed Sep 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.netgate.com/downloads/pfSense-SA-26_04.webgui.asc | [email protected] | AdvisoryRemedyVendor |
| https://github.com/pfsense/pfsense/commit/9363ac5b8651a1c7a333180425ce7719070f95f9 | [email protected] | Source CodeVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Netgate pfSense Plus | <= 26.03 |
CPE
Remediation
| |
| Netgate pfSense CE | <= 2.8.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 9, 2026 | CVE Modified | CISA-ADP |
| Sep 4, 2026 | New CVE Received | [email protected] |
Volerion