Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Scadabr

First CVE: Sep 15, 2019Active for: 7 yearsTotal CVEs: 9

Scadabr is an open-source SCADA and industrial control software platform whose vulnerability profile skews strongly toward critical-severity outcomes and has an elevated tendency toward confirmed in-the-wild exploitation. The recurring weakness classes—cross-site scripting, cross-site request forgery, OS command injection, missing authentication for critical functions, and session fixation—reflect the web-facing nature of the platform and underscore the exposure risk inherent to internet-accessible industrial control interfaces. Defenders should treat updates to this vendor as high-priority for any exposed deployments; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
22.2%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Scadabr over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 15, 2019
6 years ago
Most Recent CVE
May 19, 2026
66 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-26828HIGH
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.
Jun 11, 20218.883YESNO
CVE-2021-26829MEDIUM
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.
Jun 11, 20215.481YESNO
CVE-2026-8605CRITICAL
In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin.
May 19, 20269.838NONO
CVE-2026-8603CRITICAL
In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.
May 19, 20269.838NONO
CVE-2026-8602CRITICAL
In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and i
May 19, 20269.137NONO
CVE-2026-8604HIGH
In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any logged-in user to a malicious we
May 19, 20268.835NONO
CVE-2019-16344MEDIUM
A cross-site scripting (XSS) vulnerability in the login form (/ScadaBR/login.htm) in ScadaBR 1.0CE allows a remote attacker to inject arbitrary web script or HTML via the username
Oct 14, 20196.121NONO
CVE-2019-16321MEDIUM
ScadaBR 1.0CE, and 1.1.x through 1.1.0-RC, has XSS via a request for a nonexistent resource, as demonstrated by the dwr/test/ PATH_INFO.
Sep 15, 20196.121NONO
CVE-2025-70973MEDIUM
ScadaBR 1.12.4 is vulnerable to Session Fixation. The application assigns a JSESSIONID session cookie to unauthenticated users and does not regenerate the session identifier after
Mar 9, 20264.817NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
44%
22%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High1 (11.1%)
Unknown0 (0.0%)
User Interaction
None5 (55.6%)
Unknown0 (0.0%)
Required4 (44.4%)
Privileges Required
Low2 (22.2%)
High0 (0.0%)
None7 (77.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
2 CVEs
22.2% of CVEs· 100th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Scadabr.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Scadabr — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Scadabr's Products

View all 2 CNAs →

Top CWEs