Domoticz

Domoticz

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 07.08.2026 20:20:09
  • Zuletzt bearbeitet 17.08.2026 17:16:37

Domoticz versions prior to 2026.3 contains a stored cross-site scripting vulnerability in the mobile dashboard that allows authenticated attackers to inject arbitrary HTML and JavaScript by updating Text or Alert subtype device values through the API...

  • EPSS 0.19%
  • Veröffentlicht 05.08.2026 12:26:13
  • Zuletzt bearbeitet 10.08.2026 12:17:28

Domoticz's MochadTCP::MatchLine handler for MOCHAD_RFSEC messages (hardware/MochadTCP.cpp) copies network-received data from the up-to-1028-byte m_mochadbuffer into a fixed 50-byte stack buffer tempRFSECbuf using strcpy with no length check, across t...

  • EPSS 0.21%
  • Veröffentlicht 25.03.2026 18:12:52
  • Zuletzt bearbeitet 14.07.2026 16:16:46

Domoticz versions prior to 2026.1 contain a stored cross-site scripting vulnerability in the Add Hardware and rename device functionality of the web interface that allows authenticated administrators to execute arbitrary scripts by supplying crafted ...

Exploit
  • EPSS 0.68%
  • Veröffentlicht 23.08.2019 13:15:10
  • Zuletzt bearbeitet 21.11.2024 04:28:50

Domoticz 4.10717 has XSS via item.Name.

Exploit
  • EPSS 17.27%
  • Veröffentlicht 31.03.2019 21:29:00
  • Zuletzt bearbeitet 21.11.2024 04:19:44

Domoticz before 4.10579 neglects to categorize \n and \r as insecure argument options.

  • EPSS 7.55%
  • Veröffentlicht 31.03.2019 14:29:00
  • Zuletzt bearbeitet 21.11.2024 04:19:42

Domoticz before 4.10578 allows SQL Injection via the idx parameter in CWebServer::GetFloorplanImage in WebServer.cpp.