← Vulnerability feed

Vulnerability record · CVE-2024-54779 · published 14 May 2025

CVE-2024-54779: Netgate pfsense ce cross-site scripting vulnerability

Netgate · Pfsense Ce

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php.

5.4 CVSS 3.1 Medium EPSS 8.5% · top 5.2% CWE-79 · Cross-site scripting
5.4CVSS 3.1 base score
8.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
3References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-54779 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-27100Netgate pfsense plus improper restriction of authentication attempts vulnerabilityImproper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software…EPSS 9.8%8.8CVE-2024-54780Netgate pfsense ce code injection vulnerabilityNetgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to impro…EPSS 12%8.8CVE-2023-48123pfSense web GUI packet_capture.php remote code executionpfSense Plus 23.05.1 and earlier and pfSense CE 2.7.0 allow a remote attacker to execute arbitrary code through a crafted request to packet_capture.p…EPSS 68%analysed8.8CVE-2023-42326pfSense WebGUI GIF/GRE Interface Command InjectionNetgate pfSense 2.7.0 contains a command injection flaw in the interfaces_gif_edit.php and interfaces_gre_edit.php WebGUI components. A remote attack…EPSS 64%analysed8.8CVE-2022-24299Netgate pfsense improper input validation vulnerabilityImproper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software version…EPSS 1.9%8.8CVE-2022-26019Netgate pfsense path traversal vulnerabilityImproper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions …EPSS 4.5%6.1CVE-2021-20729Netgate pfsense plus cross-site scripting vulnerabilityCross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and pfSense Plus software versions…EPSS 2.9%5.9CVE-2023-48795SSH Terrapin attack downgrades channel integrity in OpenSSH and many SSH implementationsThe SSH transport protocol with certain OpenSSH extensions mishandles the handshake and sequence numbers, letting a remote attacker omit packets from…EPSS 93%analysed

Source: NIST National Vulnerability Database (record CVE-2024-54779), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.