← Vulnerability feed

Vulnerability record · CVE-2026-19657 · published 12 August 2026

CVE-2026-19657: Scada-lts cross-site scripting vulnerability

Scada Lts · Scada Lts

ScadaLTS 2.7.8.1 reflects user-supplied input into an HTML response without sanitization. An unauthenticated attacker who lures a victim into visiting a crafted URL can execute arbitrary JavaScript in the context of the victim's browser session.

6.1 CVSS 3.1 Medium EPSS 0.28% · top 81.8% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
0.28%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
25 Aug 2026Last modified by NVD

Description

ScadaLTS 2.7.8.1 reflects user-supplied input into an HTML response without sanitization. An unauthenticated attacker who lures a victim into visiting a crafted URL can execute arbitrary JavaScript in the context of the victim's browser session.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-19657 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-19656Scada-lts missing authorization vulnerabilityScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privil…EPSS 0.52%8.8CVE-2023-33472Scada-lts code injection vulnerabilityAn issue was discovered in Scada-LTS v2.7.5.2 build 4551883606 and before, allows remote attackers with low-level authentication to escalate privileg…EPSS 1.3%8.8CVE-2022-41976Scada-lts vulnerabilityAn privilege escalation issue was discovered in Scada-LTS 2.7.1.1 build 2948559113 allows remote attackers, authenticated in the application as a low…EPSS 1.5%5.3CVE-2024-7901Scada-lts cross-site scripting vulnerabilityA vulnerability has been found in Scada-LTS 2.7.8 and classified as problematic. Affected by this vulnerability is an unknown functionality of the fi…EPSS 0.36%2.1CVE-2025-13791Scada-lts path traversal vulnerabilityA vulnerability was identified in Scada-LTS up to 2.7.8.1. Affected is the function Common.getHomeDir of the file br/org/scadabr/vo/exporter/ZIPProje…EPSS 0.47%2.1CVE-2025-13790Scada-lts cross-site request forgery vulnerabilityA vulnerability was determined in Scada-LTS up to 2.7.8.1. This impacts an unknown function. This manipulation causes cross-site request forgery. The…EPSS 0.26%2.1CVE-2025-9139Scada-lts information exposure vulnerabilityA vulnerability was determined in Scada-LTS 2.7.8.1. Affected by this vulnerability is an unknown functionality of the file /Scada-LTS/dwr/call/plain…EPSS 0.33%2.0CVE-2025-9388Scada-lts cross-site scripting vulnerabilityA vulnerability was determined in Scada-LTS up to 2.7.8.1. This impacts an unknown function of the file watch_list.shtm. Executing manipulation of th…EPSS 0.29%

Source: NIST National Vulnerability Database (record CVE-2026-19657), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.