XSS in Netgate pfSense RSS Widget (V2.8.1, 25.11.1/26.03)
CVE-2026-38961 Published on September 4, 2026
Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense Plus (versions 26.03, 25.11.1) and pfSense CE (version 2.8.1) allows remote authenticated attackers to inject arbitrary JavaScript via malicious content in an RSS feed title. The injected script executes in the browser of any authenticated user who views the dashboard, due to insufficient sanitization of feed title data before rendering in the widget.
Vulnerability Analysis
CVE-2026-38961 can be exploited with network access, requires user interaction and a small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and no impact on availability.
Weakness Type
What is a XSS Vulnerability?
The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVE-2026-38961 has been classified to as a XSS vulnerability or weakness.
Products Associated with CVE-2026-38961
Want to know whenever a new CVE is published for Netgate Pfsense? stack.watch will email you.