CVE-2019-10664: Domoticz

Critical severity, CVSS 9.8. EPSS: 8.2% chance of exploitation in the next 30 days.

Domoticz before 4.10578 allows SQL Injection via the idx parameter in CWebServer::GetFloorplanImage in WebServer.cpp.

Affected products

  • Domoticz Domoticz: before 4.10578 (fixed in 4.10578)

Published 2019-03-31. Last modified 2026-06-17.