VulnSea

scada-lts has 5 CVEs on record between 2025 and 2026. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 6.5 (medium). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
Last 90 days
3 prev 0

Products

  • Scada-LTS 5
5
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

scada-lts vulnerabilities

CVEs affecting scada-lts, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-84860High· 8.8
6d ago

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authorization Bypass Spring Security gates DWR endpoints by URL path pattern, but DWR itself dispatches method calls based on the POST body parameters c0-scriptName and c0-met…

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authorization Bypass Spring Security gates DWR endpoints by URL path pattern, but DWR itself dispatches method calls based on the POST body parameters c0-scriptName and c0-met…

TwilightScada-LTS · Scada-LTSEPSS 0.48%via NVD
CVE-2026-84858High· 8.8
6d ago

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox Bypass The DWR "DataSourceEditDwr" class exposes the "validateScript" method that compiles and executes attacker-supp…

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox Bypass The DWR "DataSourceEditDwr" class exposes the "validateScript" method that compiles and executes attacker-supp…

TwilightScada-LTS · Scada-LTSEPSS 0.68%via NVD
CVE-2026-84859Medium· 6.5
6d ago

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Blind SQL Injection The /api/events/search endpoint accepts a JSON body containing a sortBy array

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Blind SQL Injection The /api/events/search endpoint accepts a JSON body containing a sortBy array. The values in this array are concatenated directly into the SQ…

SunlitScada-LTS · Scada-LTSEPSS 0.30%via NVD
CVE-2025-13791Medium· 6.3
9mo ago

A vulnerability was identified in Scada-LTS up to 2.7.8.1

A vulnerability was identified in Scada-LTS up to 2.7.8.1. Affected is the function Common.getHomeDir of the file br/org/scadabr/vo/exporter/ZIPProjectManager.java of the component Project Import. Such manipulation leads to path traversa…

Sunlitscada-lts · scada-ltsEPSS 0.47%via NVD
CVE-2025-13790Medium· 4.3
9mo ago

A vulnerability was determined in Scada-LTS up to 2.7.8.1

A vulnerability was determined in Scada-LTS up to 2.7.8.1. This impacts an unknown function. This manipulation causes cross-site request forgery. The attack may be initiated remotely. The exploit has been publicly disclosed and may be ut…

Sunlitscada-lts · scada-ltsEPSS 0.26%via NVD
scada-lts vulnerabilities (CVEs) · VulnSea