AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-1001

MEDIUM · CVSS 4.8 EPSS 0.21%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-03-25 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.8. See the original NVD description below for full technical details.

CVE
CVE-2026-1001
Severity
MEDIUM
CVSS
4.8
EPSS
0.21%

Original NVD Description

Domoticz versions prior to 2026.1 contain a stored cross-site scripting vulnerability in the Add Hardware and rename device functionality of the web interface that allows authenticated administrators to execute arbitrary scripts by supplying crafted names containing script or HTML markup. Attackers can inject malicious code that is stored and rendered without proper output encoding, causing script execution in the browsers of users viewing the affected page and enabling unauthorized actions within their session context.

Related CVEs

Other vulnerabilities affecting the same vendor(s)