CVE-2026-11425
- EPSS 0.16%
- Veröffentlicht 07.08.2026 20:20:09
- Zuletzt bearbeitet 17.08.2026 17:16:37
Domoticz versions prior to 2026.3 contains a stored cross-site scripting vulnerability in the mobile dashboard that allows authenticated attackers to inject arbitrary HTML and JavaScript by updating Text or Alert subtype device values through the API...
CVE-2026-71265
- EPSS 0.19%
- Veröffentlicht 05.08.2026 12:26:13
- Zuletzt bearbeitet 10.08.2026 12:17:28
Domoticz's MochadTCP::MatchLine handler for MOCHAD_RFSEC messages (hardware/MochadTCP.cpp) copies network-received data from the up-to-1028-byte m_mochadbuffer into a fixed 50-byte stack buffer tempRFSECbuf using strcpy with no length check, across t...
CVE-2026-1001
- EPSS 0.21%
- Veröffentlicht 25.03.2026 18:12:52
- Zuletzt bearbeitet 14.07.2026 16:16:46
Domoticz versions prior to 2026.1 contain a stored cross-site scripting vulnerability in the Add Hardware and rename device functionality of the web interface that allows authenticated administrators to execute arbitrary scripts by supplying crafted ...
CVE-2019-15480
- EPSS 0.68%
- Veröffentlicht 23.08.2019 13:15:10
- Zuletzt bearbeitet 21.11.2024 04:28:50
Domoticz 4.10717 has XSS via item.Name.
CVE-2019-10678
- EPSS 17.27%
- Veröffentlicht 31.03.2019 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:19:44
Domoticz before 4.10579 neglects to categorize \n and \r as insecure argument options.
CVE-2019-10664
- EPSS 7.55%
- Veröffentlicht 31.03.2019 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:19:42
Domoticz before 4.10578 allows SQL Injection via the idx parameter in CWebServer::GetFloorplanImage in WebServer.cpp.