Emoncms 11.7.3 is vulnerable to Cross Site in the input handling mechanism. This vulnerability allows authenticated attackers with API access to inject malicious JavaScript code that executes when administrators view the application logs.
References
| Link | Resource |
|---|---|
| https://github.com/emoncms/emoncms/issues/1940 | Exploit Issue Tracking Third Party Advisory |
Configurations
History
28 Oct 2025, 02:32
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/emoncms/emoncms/issues/1940 - Exploit, Issue Tracking, Third Party Advisory | |
| First Time |
Openenergymonitor
Openenergymonitor emoncms |
|
| CPE | cpe:2.3:a:openenergymonitor:emoncms:11.7.3:*:*:*:*:*:*:* |
24 Oct 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-79 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
24 Oct 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-24 15:15
Updated : 2025-10-28 02:32
NVD link : CVE-2025-60936
Mitre link : CVE-2025-60936
CVE.ORG link : CVE-2025-60936
JSON object : View
Products Affected
openenergymonitor
- emoncms
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
