CVE detail
CVE-2019-16915 — CVE-2019-16915
Published 2019-09-26 · Modified 2026-06-17 · Vendor netgate · Product pfsense · Source nvd
CRITICAL
severity
CVSS-derived band
0.0374
EPSS probability
exploitation probability, 30d
89.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
An issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter directly without sanitization (e.g., a basename call) for a pathname to file_get_contents or file_put_contents.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References