Vulnerabilities (CVE)

Filtered by vendor Domoticz Subscribe
Filtered by product Domoticz
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-1001 1 Domoticz 1 Domoticz 2026-07-14 N/A 4.8 MEDIUM
Domoticz versions prior to 2026.1 contain a stored cross-site scripting vulnerability in the Add Hardware and rename device functionality of the web interface that allows authenticated administrators to execute arbitrary scripts by supplying crafted names containing script or HTML markup. Attackers can inject malicious code that is stored and rendered without proper output encoding, causing script execution in the browsers of users viewing the affected page and enabling unauthorized actions within their session context.
CVE-2019-15480 1 Domoticz 1 Domoticz 2026-06-17 3.5 LOW 5.4 MEDIUM
Domoticz 4.10717 has XSS via item.Name.
CVE-2019-10678 1 Domoticz 1 Domoticz 2026-06-17 5.0 MEDIUM 7.5 HIGH
Domoticz before 4.10579 neglects to categorize \n and \r as insecure argument options.
CVE-2019-10664 1 Domoticz 1 Domoticz 2026-06-17 7.5 HIGH 9.8 CRITICAL
Domoticz before 4.10578 allows SQL Injection via the idx parameter in CWebServer::GetFloorplanImage in WebServer.cpp.