PT-2026-69129 · Domoticz · Domoticz
CVSS v3.1
4.4
Medium
| Vector | AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Domoticz versions prior to 2026.3
Description
A stored cross-site scripting issue exists in the mobile dashboard. Authenticated attackers can inject arbitrary HTML and JavaScript by updating device values of the Text or Alert subtypes through the API. The mobile dashboard renders this data using
ng-bind-html with an nl2br() transform that fails to perform HTML escaping. This allows malicious payloads to be stored and executed in an administrator's browser when viewing the dashboard, potentially leading to session cookie theft and account takeover.Recommendations
Update to version 2026.3 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Domoticz