← Vulnerability feed

Vulnerability record · CVE-2022-29273 · published 22 February 2023

CVE-2022-29273: pfSense WebGUI URL Table Alias XSS

Netgate · Pfsense

pfSense CE through 2.6.0 and pfSense Plus before 22.05 are vulnerable to reflected cross-site scripting in the WebGUI via URL Table Alias URL parameters. An attacker who can lure an authenticated administrator to a crafted link can execute script in the admin's browser session.

6.1 CVSS 3.1 Medium EPSS 60% · top 0.9% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

medium priorityMedium severity reflected XSS requiring user interaction, with no known in-the-wild exploitation despite a high EPSS score.

What it is

pfSense CE through 2.6.0 and pfSense Plus before 22.05 are vulnerable to reflected cross-site scripting in the WebGUI via URL Table Alias URL parameters. An attacker who can lure an authenticated administrator to a crafted link can execute script in the admin's browser session.

Impact

Successful exploitation lets an attacker run arbitrary script in the context of a logged-in pfSense administrator, enabling session theft or privileged actions through the WebGUI.

Attack surface

Reached over the network through the WebGUI URL Table Alias URL parameter; the CVSS vector indicates no privileges required but user interaction is required, so an authenticated admin must be induced to open a crafted link.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented, but EPSS is high at roughly 0.596 (99th percentile), suggesting elevated likelihood of attempted exploitation; references include a patch and release notes.

What to do

  • Upgrade pfSense CE to a release after 2.6.0 or pfSense Plus to 22.05 or later per the vendor advisory
  • Apply the fix referenced in the pfSense Redmine issue 13060
  • Restrict WebGUI administrative access to trusted management networks
  • Warn administrators against opening untrusted links while logged into the WebGUI

Detection

  • Review WebGUI access logs for requests containing script-like payloads in URL Table Alias URL parameters
  • Monitor for anomalous administrative sessions or unexpected configuration changes following admin browsing
  • Alert on crafted links referencing the URL Table Alias page delivered to administrators

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-29273 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-16915Netgate pfsense path traversal vulnerabilityAn issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter directly without sanitization (e…EPSS 3.7%9.8CVE-2019-12585Apcupsd os command injection vulnerabilityApcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status.php.EPSS 5.0%9.6CVE-2020-21487Netgate pfsense cross-site scripting vulnerabilityCross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFol…EPSS 0.67%8.8CVE-2023-48123pfSense web GUI packet_capture.php remote code executionpfSense Plus 23.05.1 and earlier and pfSense CE 2.7.0 allow a remote attacker to execute arbitrary code through a crafted request to packet_capture.p…EPSS 68%analysed8.8CVE-2023-42326pfSense WebGUI GIF/GRE Interface Command InjectionNetgate pfSense 2.7.0 contains a command injection flaw in the interfaces_gif_edit.php and interfaces_gre_edit.php WebGUI components. A remote attack…EPSS 64%analysed8.8CVE-2023-27253pfSense restore_rrddata() command injection via crafted XML configNetgate pfSense 2.7.0 contains a command injection flaw in the restore_rrddata() function. An authenticated attacker can supply a crafted XML file to…EPSS 90%analysed8.8CVE-2022-24299Netgate pfsense improper input validation vulnerabilityImproper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software version…EPSS 1.9%8.8CVE-2022-26019Netgate pfsense path traversal vulnerabilityImproper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions …EPSS 4.5%

Source: NIST National Vulnerability Database (record CVE-2022-29273), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.