Stored Cross-Site Scripting Vulnerability in Domoticz Mobile Dashboard
CVE-2026-11425
2LOW
What is CVE-2026-11425?
The mobile dashboard of Domoticz prior to version 2026.3 is susceptible to a stored cross-site scripting attack. Authenticated users can exploit the vulnerability by sending arbitrary HTML and JavaScript payloads via the API when updating device values of the Text or Alert subtype. The dashboard’s rendering mechanism employs ng-bind-html without sufficient HTML escaping, permitting malicious content to be stored and executed in the administrator's browser when accessing the mobile interface. This flaw could facilitate session cookie theft and risk account takeover, underscoring the urgent need for updates.
Affected Version(s)
Domoticz 0
