VendorsOpenEnergyMonitoremoncms11.7.3
Vulnerabilities

OpenEnergyMonitor Emoncms 11.7.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2025-60938
Emoncms 11.7.3 has a remote code execution vulnerability in the firmware upload feature that allows authenticated users to execute arbitrary commands on the target system. The vulnerability stems from insufficient input validation of user-controlled parameters including filename, port, baud_rate, core, and autoreset within the /admin/upload-custom-firmware endpoint.
Published 2025-10-24 · Analyzed
7.5EPSS 0.006
CVE-2025-60936
Emoncms 11.7.3 is vulnerable to Cross Site in the input handling mechanism. This vulnerability allows authenticated attackers with API access to inject malicious JavaScript code that executes when administrators view the application logs.
Published 2025-10-24 · Analyzed
6.1EPSS 0.002