OsVault/npm/fuxa-server
npm1 critical

fuxa-server

21 known vulnerabilities · 1 critical · 2 high

GHSA-8ghr-w65f-j3qr

FUXA's scheduler API missing admin check enables operator-to-admin escalation via scheduled device actions

Published Jun 8, 2026
GHSA-h9fj-c2qr-76g2

FUXA has SQL Injection in its TDengine DAQ connector via backslash bypass of escapeTdString

Published Jun 8, 2026
CVE-2026-25752

FUXA Unauthenticated Remote Arbitrary Device Tag Write

Published Feb 5, 2026
CVE-2023-31719CRITICAL

FUXA SQL Injection vulnerability

Published Sep 22, 2023
CVE-2023-31717HIGH

FUXA SQL Injection vulnerability

Published Sep 22, 2023
CVE-2026-25951

FUXA Affected by a Path Traversal Sanitization Bypass

Published Feb 10, 2026
CVE-2026-25895

FUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API

Published Feb 5, 2026
CVE-2025-69981

FUXA contains an Unrestricted File Upload vulnerability

Published Feb 3, 2026
CVE-2026-25939

FUXA Unauthenticated Remote Arbitrary Scheduler Write

Published Feb 10, 2026
CVE-2026-25893

FUXA Unauthenticated Remote Code Execution via Admin JWT Minting

Published Feb 5, 2026
CVE-2025-69971

Duplicate Advisory: FUXA contains a hard-coded credential vulnerability

Published Feb 3, 2026
CVE-2026-25938

FUXA Unauthenticated Remote Code Execution in Node-RED Integration

Published Feb 10, 2026
CVE-2025-69970

FUXA contains an insecure default configuration vulnerability

Published Feb 3, 2026
GHSA-w86f-rf9w-h3x6

FUXA: Unauthenticated SSRF via Socket.IO DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY with response reading

Published Jun 8, 2026
CVE-2023-31718HIGH

FUXA local file inclusion vulnerability

Published Sep 22, 2023
CVE-2026-25751

FUXA Unauthenticated Exposure of Plaintext Database Credentials

Published Feb 5, 2026
CVE-2025-69983

FUXA allows Remote Code Execution (RCE) via the project import functionality.

Published Feb 3, 2026
GHSA-fwcm-rqvw-j3p7

FUXA has an unauthenticated arbitrary tag value disclosure via /api/getTagValue

Published May 26, 2026
GHSA-rg3m-cfq7-g6h6

FUXA Vulnerable to Unauthenticated Remote Code Execution via Script Test Mode Authorization Bypass

Published May 26, 2026
GHSA-q3w6-q3hc-c5x6

FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device Configurations

Published May 27, 2026
GHSA-r9g5-7q8j-958c

FUXA provides guest and invalid-token access to protected read APIs in secure mode

Published May 28, 2026
Check your entire dependency tree at onceRun dependency scan →