Openenergymonitor

Emoncms

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.06%
  • Veröffentlicht 24.10.2025 00:00:00
  • Zuletzt bearbeitet 28.10.2025 02:32:52

Emoncms 11.7.3 is vulnerable to Cross Site in the input handling mechanism. This vulnerability allows authenticated attackers with API access to inject malicious JavaScript code that executes when administrators view the application logs.

Exploit
  • EPSS 0.4%
  • Veröffentlicht 24.10.2025 00:00:00
  • Zuletzt bearbeitet 28.10.2025 02:32:37

Emoncms 11.7.3 has a remote code execution vulnerability in the firmware upload feature that allows authenticated users to execute arbitrary commands on the target system. The vulnerability stems from insufficient input validation of user-controlled ...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 06.02.2025 19:15:19
  • Zuletzt bearbeitet 30.07.2025 18:12:48

A SQL Injection vulnerability exists in the /feed/insert.json endpoint of the Emoncms project >= 11.6.9. The vulnerability is caused by improper handling of user-supplied input in the data query parameter, allowing attackers to execute arbitrary SQL ...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 21.02.2021 06:15:12
  • Zuletzt bearbeitet 21.11.2024 05:56:44

Modules/input/Views/schedule.php in Emoncms through 10.2.7 allows XSS via the node parameter.

Exploit
  • EPSS 0.34%
  • Veröffentlicht 15.07.2019 02:15:10
  • Zuletzt bearbeitet 21.11.2024 04:17:54

OpenEnergyMonitor Project Emoncms 9.8.8 is affected by: Cross Site Scripting (XSS). The impact is: Theoretically low, but might potentially enable persistent XSS (user could embed mal. code). The component is: Javascript code execution in "Name", "Lo...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 12.02.2017 04:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An issue was discovered in Emoncms through 9.8.0. The vulnerability exists due to insufficient filtration of user-supplied data in multiple HTTP GET parameters passed to the "emoncms-master/Modules/vis/visualisations/compare.php" URL. An attacker cou...