CVE-2025-60936

Emoncms 11.7.3 is vulnerable to Cross Site in the input handling mechanism. This vulnerability allows authenticated attackers with API access to inject malicious JavaScript code that executes when administrators view the application logs.
References
Link Resource
https://github.com/emoncms/emoncms/issues/1940 Exploit Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:openenergymonitor:emoncms:11.7.3:*:*:*:*:*:*:*

History

28 Oct 2025, 02:32

Type Values Removed Values Added
References () https://github.com/emoncms/emoncms/issues/1940 - () https://github.com/emoncms/emoncms/issues/1940 - Exploit, Issue Tracking, Third Party Advisory
First Time Openenergymonitor
Openenergymonitor emoncms
CPE cpe:2.3:a:openenergymonitor:emoncms:11.7.3:*:*:*:*:*:*:*

24 Oct 2025, 17:15

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

24 Oct 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-24 15:15

Updated : 2025-10-28 02:32


NVD link : CVE-2025-60936

Mitre link : CVE-2025-60936

CVE.ORG link : CVE-2025-60936


JSON object : View

Products Affected

openenergymonitor

  • emoncms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')