CVE-2021-26829
OpenPLC ScadaBR Cross-site Scripting Vulnerability
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.
MEDIUM · CVSS 5.4
⚠ CISA KEV
EPSS 0.07564
Act now
- Listed on CISA KEV (known exploited in the wild)
- SSVC exploitation status: active
- EPSS percentile: top 8% of all CVEs by exploitation likelihood
- Public exploit or PoC is available
Sigma rules7
YARA rules0