CVE Explorer
CVE-2026-1001
Domoticz versions prior to 2026.1 contain a stored cross-site scripting vulnerability in the Add Hardware and rename device functionality of the web interface that allows authenticated administrators to execute arbitrary scripts by supplying crafted names containing script or HTML markup. Attackers can inject malicious code that is stored and rendered without proper output encoding, causing script execution in the browsers of users viewing the affected page and enabling unauthorized actions with
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","packageURL":"pkg:github/domoticz/domoticz","product":"Domoticz","repo":"https://github.com/domoticz/domoticz","vendor":"Domoticz","versions":[{"lessThan":"2026.1","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:a3f0d26e2ffadaeecab93bca761ad73631b0dd43c4984ae500782f2bab926daa · sha256:4af5a4ce055dbf0c… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":4.8,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"HIGH","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","userInteraction":"PASSIVE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:a3f0d26e2ffadaeecab93bca761ad73631b0dd43c4984ae500782f2bab926daa · sha256:4af5a4ce055dbf0c… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-79","description":"CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a3f0d26e2ffadaeecab93bca761ad73631b0dd43c4984ae500782f2bab926daa · sha256:4af5a4ce055dbf0c… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["release-notes","patch"],"url":"https://www.domoticz.com/2026.1/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a3f0d26e2ffadaeecab93bca761ad73631b0dd43c4984ae500782f2bab926daa · sha256:4af5a4ce055dbf0c… · /containers/cna/references/0
{"tags":["third-party-advisory"],"url":"https://www.vulncheck.com/advisories/domoticz-stored-xss-via-hardware-configuration-endpoint"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a3f0d26e2ffadaeecab93bca761ad73631b0dd43c4984ae500782f2bab926daa · sha256:4af5a4ce055dbf0c… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.