CVE-2022-40965: Deltaww Diaenergie

Medium severity, CVSS 5.4. EPSS: 11.1% chance of exploitation in the next 30 days.

The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PostEnergyType API.

Affected products

  • Deltaww Diaenergie: before 1.9.01.002 (fixed in 1.9.01.002)

Published 2022-10-27. Last modified 2026-06-17.