CVE-2011-5047: Pfsense

Medium severity, CVSS 4.3. EPSS: 1.1% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in status_rrd_graph.php in pfSense before 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the style parameter.

Affected products

  • Pfsense Pfsense: up to and including 2.0; version 1.0.x only; version 1.2.1 only; version 1.2.2 only; version 1.2.3 only

Published 2012-01-03. Last modified 2026-06-16.