Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Opnsense Project

First CVE: Jan 3, 2018Active for: 9 yearsTotal CVEs: 37

Opnsense is a firewall and network security appliance built on an open-source foundation, with a focused product footprint centered on its core firewall platform. The observed vulnerability pattern centers on cross-site request forgery weaknesses in the administrative interface, reflecting the web-based management surface of network appliances. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
37
Total CVEs
Bottom 1%
6.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 84% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Opnsense Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 3, 2018
8 years ago
Most Recent CVE
May 13, 2026
73 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (37 CVEs).

37 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-1000479HIGH
pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrary code, because the error detection occu
Jan 3, 20188.855NOYES
CVE-2026-44194CRITICAL
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE) vulnerability in the OPNsense core allows a user with user-
May 13, 20269.139NONO
CVE-2026-45158CRITICAL
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP configuration of the configured interface, which is process
May 13, 20269.136NONO
CVE-2023-39007CRITICAL
/ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows XSS via openAction in app/controllers/OPNsense/Cron/Ite
Aug 9, 20239.636NOYES
CVE-2026-44193CRITICAL
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the XMLRPC method opnsense.restore_config_section fails to sanitize user supplied input leading to Remot
May 13, 20269.135NONO
CVE-2025-50989CRITICAL
OPNsense before 25.1.8 contains an authenticated command injection vulnerability in its Bridge Interface Edit endpoint (interfaces_bridge_edit.php). The span POST parameter is conc
Aug 27, 20259.132NONO
CVE-2023-39004CRITICAL
Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attackers to access sensitive inform
Aug 9, 20239.832NONO
CVE-2023-39008CRITICAL
A command injection vulnerability in the component /api/cron/settings/setJob/ of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execu
Aug 9, 20239.830NONO
CVE-2020-23015MEDIUM
An open redirect issue was discovered in OPNsense through 20.1.5. The redirect parameter "url" in login page was not filtered and can redirect user to any website.
May 3, 20216.130NOYES
CVE-2026-34578HIGH
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.6, OPNsense's LDAP authentication connector passes the login username directly into an LDAP search filter w
Apr 9, 20268.228NONO
View all 37 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products37 CVEs
57%
19%
24%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network37 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low37 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None15 (40.5%)
Unknown0 (0.0%)
Required22 (59.5%)
Privileges Required
Low7 (18.9%)
High6 (16.2%)
None24 (64.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (37 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.7% of CVEs· 99th percentile
Nuclei
3 CVEs
8.1% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Opnsense Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Opnsense Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Opnsense Project's Products

View all 3 CNAs →

Top CWEs