CVE-2023-44276: Opnsense

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

OPNsense before 23.7.5 allows XSS via the index.php sequence parameter to the Lobby Dashboard.

Affected products

  • Opnsense Opnsense: before 23.7.5 (fixed in 23.7.5)

Published 2023-09-28. Last modified 2026-06-17.