peter bassill · operator
$ cve CVE-2021-26829 JSON

CVE-2021-26829 KEV

5.4
MEDIUM · CVSS 3.1 · EPSS 48.1% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2025-12-19.

Description

OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.

Scoring

CVSS5.4 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS48.05% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-79
On CISA KEVyes — remediate by 2025-12-19
Public exploitnone known
Published2021-06-11
Last modified2026-06-17

CISA KEV

NameOpenPLC ScadaBR Cross-site Scripting Vulnerability
Added2025-11-28
Due2025-12-19
Vendor / productOpenPLC / ScadaBR
Ransomware usenone reported

Affected (3)

VendorProduct
linuxlinux kernel
microsoftwindows
scadabrscadabr

References

→ the Explorer  ·  watch your stack  ·  NVD