Vendorsfrangoteamfuxaany version
Vulnerabilities

frangoteam FUXA any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2026-25893
FUXA Unauthenticated Remote Code Execution via Admin JWT Minting
Published 2026-02-09 · Analyzed
10.0EPSS 0.011
CVE-2023-31719
FUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin.
Published 2023-09-21 · Modified
9.8EPSS 0.260
CVE-2026-25895
FUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API
Published 2026-02-09 · Analyzed
9.81 PoCEPSS 0.062
CVE-2025-69985
FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, which improperly trusts the HTTP "Referer" header to validate internal requests. A remote unauthenticated attacker can bypass JWT authentication by spoofing the Referer header to match the server's host. Successful exploitation allows the attacker to access the protected /api/runscript endpoint and execute arbitrary Node.js code on the server.
Published 2026-02-24 · Analyzed
9.81 PoCEPSS 0.057
CVE-2026-25938
FUXA Unauthenticated Remote Code Execution in Node-RED Integration
Published 2026-02-09 · Analyzed
9.8EPSS 0.013
CVE-2026-25894
FUXA Unauthenticated Remote Code Execution via Hardcoded JWT Secret in Default Configuration
Published 2026-02-09 · Analyzed
9.8EPSS 0.012
CVE-2026-25939
FUXA Unauthenticated Remote Arbitrary Scheduler Write
Published 2026-02-09 · Analyzed
9.3EPSS 0.008
CVE-2026-25752
FUXA Unauthenticated Remote Arbitrary Device Tag Write
Published 2026-02-06 · Analyzed
9.3EPSS 0.007
CVE-2026-25751
FUXA Unauthenticated Exposure of Plaintext Database Credentials
Published 2026-02-06 · Analyzed
9.1EPSS 0.004
CVE-2026-25951
FUXA has a Path Traversal Sanitization Bypass
Published 2026-02-09 · Analyzed
8.6EPSS 0.017
CVE-2023-31717
A SQL Injection attack in FUXA <= 1.1.12 allows exfiltration of confidential information from the database.
Published 2023-09-21 · Modified
7.5EPSS 0.018
CVE-2023-31718
FUXA <= 1.1.12 is vulnerable to Local via Inclusion via /api/download.
Published 2023-09-21 · Modified
7.5EPSS 0.017
CVE-2023-31716
FUXA <= 1.1.12 has a Local File Inclusion vulnerability via file=fuxa.log
Published 2023-09-21 · Modified
7.5EPSS 0.014