CVE-2021-26829

MEDIUM KEV

ScadaBR < 0.9.1 - Stored Cross-Site Scripting via system_settings.shtm

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-26829 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 28, 2025.

Description

OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.

Scores

CVSS v3 5.4
EPSS 0.0993
EPSS Percentile 93.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact partial

Details

CISA KEV 2025-11-28
VulnCheck KEV 2025-10-09
ENISA EUVD EUVD-2021-13614
CWE
CWE-79
Status published
Products (1)
scadabr/scadabr < 0.9.1
Published Jun 11, 2021
KEV Added Nov 28, 2025
Tracked Since Feb 18, 2026