CVE-2025-34172: Pfsense
Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.
In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent parameter is displayed after being read from HTTP GET requests. This can enable reflected cross-site scripting when the victim is authenticated.
Affected products
- Pfsense Pfsense: before 2.8.0 (fixed in 2.8.0)
Published 2025-09-09. Last modified 2026-07-14.