Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.1

OPNsense allows attackers to inject malicious scripts via system settings

CVE-2019-25369
Summary

A vulnerability in OPNsense's system settings allows attackers to inject malicious scripts that can be executed when an authenticated user views the settings. This means that if an attacker can trick a user into accessing the settings, they can run malicious code on the system. To protect against this, update OPNsense to the latest version.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
opnsense opnsense 19.1 –
Original title
OPNsense 19.1 contains a stored cross-site scripting vulnerability in the system_advanced_sysctl.php endpoint that allows attackers to inject persistent malicious scripts via the tunable parameter....
Original description
OPNsense 19.1 contains a stored cross-site scripting vulnerability in the system_advanced_sysctl.php endpoint that allows attackers to inject persistent malicious scripts via the tunable parameter. Attackers can submit POST requests with script payloads that are stored and executed in the context of authenticated user sessions when the page is viewed.
nvd CVSS3.1 5.4
nvd CVSS4.0 5.1
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
Published: 15 Feb 2026 · Updated: 10 Mar 2026 · First seen: 6 Mar 2026