Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

OPNsense — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in OPNsense, with AI-generated Chinese analysis, references, and POCs.

This page documents known security vulnerabilities and weaknesses associated with OPNsense, a widely used open-source firewall and routing platform. It aggregates data from various security databases and vendor advisories to provide a comprehensive view of the software’s security posture. The collection includes a broad spectrum of issue types, ranging from remote code execution and privilege escalation to cross-site scripting and information disclosure. The data spans from the initial release of the product through the present day, capturing both historical findings and recently reported vulnerabilities. By consulting this resource, users can track a vendor's advisories to stay informed about critical patches and security updates. It also serves as a valuable reference for understanding a specific weakness class within the context of network security appliances, helping administrators assess risk and prioritize mitigation efforts. Furthermore, individuals can look up a product's vulnerability history to analyze trends, evaluate the effectiveness of past remediation strategies, and make informed decisions about system upgrades or configuration changes. This centralized view facilitates better security management by providing context for individual CVE entries and highlighting potential impact areas within OPNsense deployments. The information is intended to support security professionals, system administrators, and researchers in maintaining robust network defenses and ensuring the integrity of firewall infrastructure.

Vendor: OPNsense

CVE IDTitleCVSSSeverityPublished
CVE-2026-49132 OPNsense < 26.1.9 Stored XSS via Certificate Description Field CWE-79 5.4 Medium2026-08-03
CVE-2026-49131 OPNsense < 26.1.9 Stored XSS via Firewall Rule Description Field CWE-79 5.4 Medium2026-08-03
CVE-2026-2035 Deciso OPNsense diag_backup.php filename Command Injection Remote Code Execution Vulnerability CWE-78 8.0AIHighAI2026-02-20
CVE-2019-25377 OPNsense 19.1 Reflected XSS via system_advanced_sysctl.php CWE-79 5.4 Medium2026-02-15
CVE-2019-25376 OPNsense 19.1 Reflected XSS via proxy endpoint CWE-79 6.1 Medium2026-02-15
CVE-2019-25375 OPNsense 19.1 Reflected XSS via monit interface CWE-79 6.1 Medium2026-02-15
CVE-2019-25374 OPNsense 19.1 Reflected XSS via vpn_ipsec_settings.php CWE-79 6.1 Medium2026-02-15
CVE-2019-25373 OPNsense 19.1 Stored XSS via firewall_rules_edit.php CWE-79 6.4 Medium2026-02-15
CVE-2019-25371 OPNsense 19.1 Reflected XSS via diag_ping.php CWE-79 6.1 Medium2026-02-15
CVE-2019-25372 OPNsense 19.1 Reflected XSS via diag_traceroute.php CWE-79 6.1 Medium2026-02-15
CVE-2019-25370 OPNsense 19.1 Reflected XSS via interfaces_vlan_edit.php CWE-79 6.1 Medium2026-02-15
CVE-2019-25369 OPNsense 19.1 Stored XSS via system_advanced_sysctl.php CWE-79 6.4 Medium2026-02-15
CVE-2019-25368 OPNsense 19.1 Reflected XSS via diag_backup.php CWE-79 5.4 Medium2026-02-15
CVE-2025-13698 Deciso OPNsense diag_backup.php filename Directory Traversal Arbitrary File Creation Vulnerability CWE-22 5.7AIMediumAI2025-12-23
CVE-2025-34182 Deciso OPNsense < 25.7.4 /interfaces_ppps_edit.php ptpid Stored XSS CWE-79 5.4AIMediumAI2025-10-01
CVE-2025-50989 OPNsense 安全漏洞 CWE-78 9.1 Critical2025-08-27

All 16 known CVE vulnerabilities affecting OPNsense with full Chinese analysis, references, and POCs where available.