Ad

CVE-2026-1001

MEDIUM CVSS 4.0: 4.8 EPSS 0.04%
Updated Mar 26, 2026
Domoticz
Parameter Value
CVSS 4.8 (MEDIUM)
Affected Versions before 2026.1
Type CWE-79 (Cross-Site Scripting (XSS))
Vendor Domoticz
Public PoC No

Domoticz versions prior to 2026.1 contain a stored cross-site scripting vulnerability in the Add Hardware and rename device functionality of the web interface that allows authenticated administrators to execute arbitrary scripts by supplying crafted names containing script or HTML markup. Attackers can inject malicious code that is stored and rendered without proper output encoding, causing script execution in the browsers of users viewing the affected page and enabling unauthorized actions within their session context.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
High
Admin privileges needed
User Interaction
Passive
Minimal interaction

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v4.0

Vulnerable Products

domoticz:domoticz