CVE-2021-26829

OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.

Basic Information

CVE State
PUBLISHED
Reserved Date
February 05, 2021
Published Date
June 11, 2021
Last Updated
December 02, 2025
Vendor
n/a
Product
n/a
Description
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.
Tags
cisa

CVSS Scores

CVSS v3.1

5.4 - MEDIUM

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CVSS v2.0

3.5

Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

SSVC Information

Exploitation
active
Technical Impact
partial

Exploit Status

Exploited in the Wild
Yes (2026-06-01 10:45:14 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CVE 2026-06-01 10:45:14 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel