CVE-2026-84860
- EPSS 0.49%
- Veröffentlicht 16.09.2026 14:52:23
- Zuletzt bearbeitet 18.09.2026 19:18:42
ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authorization Bypass Spring Security gates DWR endpoints by URL path pattern, but DWR itself dispatches method calls based on the POST body parameters c0-scriptName and c0-methodName. The ...
CVE-2026-84859
- EPSS 0.3%
- Veröffentlicht 16.09.2026 14:52:14
- Zuletzt bearbeitet 18.09.2026 19:18:42
ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Blind SQL Injection The /api/events/search endpoint accepts a JSON body containing a sortBy array. The values in this array are concatenated directly into the SQL ORDER BY cl...
CVE-2026-84858
- EPSS 0.68%
- Veröffentlicht 16.09.2026 14:51:56
- Zuletzt bearbeitet 18.09.2026 19:18:42
ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox Bypass The DWR "DataSourceEditDwr" class exposes the "validateScript" method that compiles and executes attacker-supplied JavaScri...
CVE-2026-19657
- EPSS 0.2%
- Veröffentlicht 12.08.2026 19:14:33
- Zuletzt bearbeitet 25.08.2026 13:04:03
ScadaLTS 2.7.8.1 reflects user-supplied input into an HTML response without sanitization. An unauthenticated attacker who lures a victim into visiting a crafted URL can execute arbitrary JavaScript in the context of the victim's browser session.
CVE-2026-19656
- EPSS 0.29%
- Veröffentlicht 12.08.2026 19:10:11
- Zuletzt bearbeitet 25.08.2026 14:08:10
ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary operating system commands on the host. Successful ex...
CVE-2025-13791
- EPSS 0.46%
- Veröffentlicht 30.11.2025 15:32:05
- Zuletzt bearbeitet 03.09.2026 03:15:10
A vulnerability was identified in Scada-LTS up to 2.7.8.1. Affected is the function Common.getHomeDir of the file br/org/scadabr/vo/exporter/ZIPProjectManager.java of the component Project Import. Such manipulation leads to path traversal. The attack...
CVE-2025-13790
- EPSS 0.26%
- Veröffentlicht 30.11.2025 14:32:06
- Zuletzt bearbeitet 03.09.2026 03:15:10
A vulnerability was determined in Scada-LTS up to 2.7.8.1. This impacts an unknown function. This manipulation causes cross-site request forgery. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The v...
CVE-2025-10235
- EPSS 0.3%
- Veröffentlicht 11.09.2025 00:32:06
- Zuletzt bearbeitet 29.04.2026 01:00:01
A flaw has been found in Scada-LTS up to 2.7.8.1. This issue affects some unknown processing of the file /reports.shtm of the component Reports Module. This manipulation of the argument Colour causes cross site scripting. The attack may be initiated ...
CVE-2025-10234
- EPSS 0.3%
- Veröffentlicht 10.09.2025 23:32:06
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was detected in Scada-LTS up to 2.7.8.1. This vulnerability affects unknown code of the file /data_point_edit.shtm of the component Data Point Edit Module. The manipulation of the argument Text Renderer properties results in cross sit...
CVE-2025-9404
- EPSS 0.28%
- Veröffentlicht 25.08.2025 02:32:06
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was identified in Scada-LTS up to 2.7.8.1. The affected element is an unknown function of the file /pointHierarchySLTS of the component Folder Handler. The manipulation of the argument Title leads to cross site scripting. It is possib...