CVE-2025-60936: Openenergymonitor Emoncms

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

Emoncms 11.7.3 is vulnerable to Cross Site in the input handling mechanism. This vulnerability allows authenticated attackers with API access to inject malicious JavaScript code that executes when administrators view the application logs.

Affected products

Published 2025-10-24. Last modified 2026-06-17.