Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2914 articles · 109779 vulns · 38/41 feeds (7d)
← Back to list
5.4
CVE-2019-25377
opnsen · opnsense

OPNsense 19.1 contains a reflected cross-site scripting vulnerability in the system_advanced_sysctl.php endpoint that allows attackers to inject malicious scripts via the value parameter. Attackers ca

Description

OPNsense 19.1 contains a reflected cross-site scripting vulnerability in the system_advanced_sysctl.php endpoint that allows attackers to inject malicious scripts via the value parameter. Attackers can craft POST requests with script payloads in the value parameter to execute JavaScript in the context of authenticated user sessions.

Affected Products

VendorProductVersions
opnsenopnsense—

References

  • https://forum.opnsense.org/index.php?topic=11469.0(Release Notes)
  • https://opnsense.org(Product)
  • https://www.exploit-db.com/exploits/46351(Exploit, Third Party Advisory, VDB Entry)
  • https://www.vulncheck.com/advisories/opnsense-reflected-xss-via-systemadvancedsysctlphp(Broken Link)
CVSS 3.15.4 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CISA KEV❌ No
Actively exploited❌ No
CWECWE-79
PublishedFeb 15, 2026
Last enriched8d ago
Trending Score0
Source articles0
Independent0
Info Completeness7/14
Missing: versions, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-34578EXP
OPNsense has an LDAP Injection via Unsanitized Username in Authentication
Trending: 74
MEDIUMCVE-2019-25376
OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted payloads through the ignoreLogACL paramete
MEDIUMCVE-2019-25375
OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted input to the mailserver parameter. Attacke
MEDIUMCVE-2019-25374
OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by exploiting the passthrough_networks parameter in vpn_ipsec_settings.php. Atta
MEDIUMCVE-2019-25373
OPNsense 19.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted input to the category parameter. Attackers can

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Feb 15, 2026
Discovered by ZDM
Apr 1, 2026