Scada Lts is a narrowly focused industrial control system software platform that, despite limited product diversity, occupies a more prominent position in the vulnerability landscape than its footprint might suggest. The vendor's disclosures center on a single core product and span a range of weakness classes tied to the complexity of supervisory control and data acquisition environments. Vulnerabilities affecting this platform carry structural importance to defenders who deploy or monitor such systems, particularly where network isolation and access controls govern exposure. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Scada Lts over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-13790HIGH A vulnerability was determined in Scada-LTS up to 2.7.8.1. This impacts an unknown function. This manipulation causes cross-site request forgery. The attack may be initiated remote | Nov 30, 2025 | 8.8 | 27 | NO | NO |
CVE-2022-41976HIGH An privilege escalation issue was discovered in Scada-LTS 2.7.1.1 build 2948559113 allows remote attackers, authenticated in the application as a low-privileged user to change role | Apr 10, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-33472HIGH An issue was discovered in Scada-LTS v2.7.5.2 build 4551883606 and before, allows remote attackers with low-level authentication to escalate privileges, execute arbitrary code, and | Jan 13, 2024 | 8.8 | 23 | NO | NO |
CVE-2025-13791MEDIUM A vulnerability was identified in Scada-LTS up to 2.7.8.1. Affected is the function Common.getHomeDir of the file br/org/scadabr/vo/exporter/ZIPProjectManager.java of the component | Nov 30, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-9234MEDIUM A vulnerability was detected in Scada-LTS up to 2.7.8.1. The affected element is an unknown function of the file maintenance_events.shtm. The manipulation of the argument Alias res | Aug 20, 2025 | 5.4 | 22 | NO | NO |
CVE-2025-9404MEDIUM A vulnerability was identified in Scada-LTS up to 2.7.8.1. The affected element is an unknown function of the file /pointHierarchySLTS of the component Folder Handler. The manipula | Aug 25, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-9143MEDIUM A security flaw has been discovered in Scada-LTS 2.7.8.1. This affects an unknown part of the file mailing_lists.shtm. The manipulation of the argument name/userList/address result | Aug 19, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-9139MEDIUM A vulnerability was determined in Scada-LTS 2.7.8.1. Affected by this vulnerability is an unknown functionality of the file /Scada-LTS/dwr/call/plaincall/WatchListDwr.init.dwr. Exe | Aug 19, 2025 | 6.5 | 20 | NO | NO |
CVE-2025-10235MEDIUM A flaw has been found in Scada-LTS up to 2.7.8.1. This issue affects some unknown processing of the file /reports.shtm of the component Reports Module. This manipulation of the arg | Sep 11, 2025 | 4.8 | 19 | NO | NO |
CVE-2025-9388MEDIUM A vulnerability was determined in Scada-LTS up to 2.7.8.1. This impacts an unknown function of the file watch_list.shtm. Executing manipulation of the argument Name can lead to cro | Aug 24, 2025 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Scada Lts.
Media articles that mention a CVE ID that affects a product developed by Scada Lts — matched by CVE ID, not by vendor name.