Openenergymonitor's vulnerability profile centers on Emoncms, a web-based energy monitoring and visualization platform deployed across residential and small-business energy-management installations. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through classic web-application weakness classes including cross-site scripting, improper input validation, and SQL injection that reflect the platform's role handling user input and database queries. Defenders should prioritize patches for this vendor's web interface, particularly in internet-accessible deployments; live severity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openenergymonitor over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-22992CRITICAL A SQL Injection vulnerability exists in the /feed/insert.json endpoint of the Emoncms project >= 11.6.9. The vulnerability is caused by improper handling of user-supplied input in | Feb 6, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-60938HIGH Emoncms 11.7.3 has a remote code execution vulnerability in the firmware upload feature that allows authenticated users to execute arbitrary commands on the target system. The vuln | Oct 24, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-60936MEDIUM Emoncms 11.7.3 is vulnerable to Cross Site in the input handling mechanism. This vulnerability allows authenticated attackers with API access to inject malicious JavaScript code th | Oct 24, 2025 | 6.1 | 21 | NO | NO |
CVE-2017-5964MEDIUM An issue was discovered in Emoncms through 9.8.0. The vulnerability exists due to insufficient filtration of user-supplied data in multiple HTTP GET parameters passed to the "emonc | Feb 12, 2017 | 6.1 | 21 | NO | NO |
CVE-2021-26716MEDIUM Modules/input/Views/schedule.php in Emoncms through 10.2.7 allows XSS via the node parameter. | Feb 21, 2021 | 6.1 | 20 | NO | NO |
CVE-2019-1010008MEDIUM OpenEnergyMonitor Project Emoncms 9.8.8 is affected by: Cross Site Scripting (XSS). The impact is: Theoretically low, but might potentially enable persistent XSS (user could embed | Jul 15, 2019 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openenergymonitor.
Media articles that mention a CVE ID that affects a product developed by Openenergymonitor — matched by CVE ID, not by vendor name.