CVE-2025-60936: Openenergymonitor Emoncms
Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.
Emoncms 11.7.3 is vulnerable to Cross Site in the input handling mechanism. This vulnerability allows authenticated attackers with API access to inject malicious JavaScript code that executes when administrators view the application logs.
Affected products
- Openenergymonitor Emoncms: version 11.7.3 only
Published 2025-10-24. Last modified 2026-06-17.