Openenergymonitor / Emoncms
6 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-60938 | Emoncms 11.7.3 has a remote code execution vulnerability in the firmware upload feature that allows authenticated users to execute arbitrary commands on the ta… | HIGH | 7.5 | Oct 24, 2025 |
| CVE-2025-60936 | Emoncms 11.7.3 is vulnerable to Cross Site in the input handling mechanism. This vulnerability allows authenticated attackers with API access to inject malicio… | MEDIUM | 6.1 | Oct 24, 2025 |
| CVE-2025-22992 | A SQL Injection vulnerability exists in the /feed/insert.json endpoint of the Emoncms project >= 11.6.9. The vulnerability is caused by improper handling of us… | CRITICAL | 9.8 | Feb 6, 2025 |
| CVE-2021-26716 | Modules/input/Views/schedule.php in Emoncms through 10.2.7 allows XSS via the node parameter. | MEDIUM | 6.1 | Feb 21, 2021 |
| CVE-2019-1010008 | OpenEnergyMonitor Project Emoncms 9.8.8 is affected by: Cross Site Scripting (XSS). The impact is: Theoretically low, but might potentially enable persistent X… | MEDIUM | 5.4 | Jul 15, 2019 |
| CVE-2017-5964 | An issue was discovered in Emoncms through 9.8.0. The vulnerability exists due to insufficient filtration of user-supplied data in multiple HTTP GET parameters… | MEDIUM | 6.1 | Feb 12, 2017 |
Showing 1 to 6 of 6 CVEs