Stored Cross-Site Scripting Vulnerability in Domoticz by Domoticz
CVE-2026-1001

4.8MEDIUM

Key Information:

Vendor

Domoticz

Status
Vendor
CVE Published:
25 March 2026

What is CVE-2026-1001?

Versions of Domoticz prior to 2026.1 are susceptible to a stored cross-site scripting vulnerability, affecting the Add Hardware and rename device features. This flaw permits authenticated administrators to input specially crafted names that may include script or HTML elements. If successfully exploited, attackers can embed malicious code that gets stored and later executed in the browsers of users who access the compromised web interface. As a result, unauthorized actions can be performed within the context of user sessions, highlighting the importance of implementing secure output encoding practices to prevent such vulnerabilities.

Affected Version(s)

Domoticz 0 < 2026.1

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kacper Leszczyński
.