CVE-2022-23993: Pfsense

Medium severity, CVSS 6.1. EPSS: 1.5% chance of exploitation in the next 30 days.

/usr/local/www/pkg.php in pfSense CE before 2.6.0 and pfSense Plus before 22.01 uses $_REQUEST['pkg_filter'] in a PHP echo call, causing XSS.

Affected products

  • Pfsense Pfsense: before 2.6.0 (fixed in 2.6.0)
  • Pfsense Pfsense Plus: before 22.01 (fixed in 22.01)

Published 2022-01-26. Last modified 2026-06-17.