Emoncms 11.7.3 is vulnerable to Cross Site in the input handling mechanism. This vulnerability allows authenticated attackers with API access to inject malicious JavaScript code that executes when administrators view the application logs.
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://github.com/emoncms/emoncms/issues/1940 |     | 
History
                    Tue, 28 Oct 2025 02:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Openenergymonitor Openenergymonitor emoncms | |
| CPEs | cpe:2.3:a:openenergymonitor:emoncms:11.7.3:*:*:*:*:*:*:* | |
| Vendors & Products | Openenergymonitor Openenergymonitor emoncms | 
Mon, 27 Oct 2025 22:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Emoncms Emoncms emoncms | |
| Vendors & Products | Emoncms Emoncms emoncms | 
Fri, 24 Oct 2025 17:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics | cvssV3_1 
 
 | 
Fri, 24 Oct 2025 14:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Emoncms 11.7.3 is vulnerable to Cross Site in the input handling mechanism. This vulnerability allows authenticated attackers with API access to inject malicious JavaScript code that executes when administrators view the application logs. | |
| References |  | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mitre
Published: 2025-10-24T00:00:00.000Z
Updated: 2025-10-24T16:31:03.976Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-60936
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-10-24T16:30:59.904Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-10-24T15:15:40.440
Modified: 2025-10-28T02:32:52.333
Link: CVE-2025-60936
 Redhat
                        Redhat
                    No data.