CVE-2025-34172: Pfsense

Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.

In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent parameter is displayed after being read from HTTP GET requests. This can enable reflected cross-site scripting when the victim is authenticated.

Affected products

  • Pfsense Pfsense: before 2.8.0 (fixed in 2.8.0)

Published 2025-09-09. Last modified 2026-07-14.