PatchSiren

Domoticz CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Domoticz CVE published 2026-08-07

CVE-2026-11425

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-07T21:17:27.010Z and has not been modified since then. The vulnerability affects Domoticz versions prior to 2026.3, allowing authenticated attackers to inject arbitrary HTML and JavaScript by updating Text or Alert subtype device values through the API. The mobile dashboard renders device data via n [truncated]

HIGH domoticz CVE published 2026-08-05

CVE-2026-71265

Domoticz's MochadTCP::MatchLine() handler for MOCHAD_RFSEC messages (hardware/MochadTCP.cpp) copies network-received data from the up-to-1028-byte m_mochadbuffer into a fixed 50-byte stack buffer tempRFSECbuf using strcpy() with no length check, across three separate code branches (DS10A/KR10A/MS10A device types). An attacker on the local network segment able to reach the Mochad TCP bridge (default port 1 [truncated]

MEDIUM Domoticz CVE published 2026-03-25

CVE-2026-1001

CVE-2026-1001 is a stored cross-site scripting vulnerability in Domoticz versions prior to 2026.1. The vulnerability exists in the Add Hardware and rename device functionality of the web interface, allowing authenticated administrators to execute arbitrary scripts by supplying crafted names containing script or HTML markup. This could lead to unauthorized actions within the session context of users viewin [truncated]