Technology · npm
fuxa-server (npm) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 24 vulnerabilities in fuxa-server (npm): 0 in the last 7 days and 5 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-47721, was published on 18 August 2026.
- Last 7 days
- 0
- Last 90 days
- 5
- Critical, all time
- 0
- Exploited in the wild
- 0
About fuxa-server (npm)
A web-based SCADA/HMI platform for industrial automation.
Latest fuxa-server (npm) vulnerabilities
- CVE-2026-47721: FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, POST /api/scheduler and DELETE…mediumCVSS 6.3EPSS 0.4%
- CVE-2026-47720: FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengine DAQ storage…mediumCVSS 5.3EPSS 0.6%
- CVE-2026-47719: FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE_WEBAPI_REQUEST and…highCVSS 8.2EPSS 0.6%
- CVE-2026-43947: frangoteam FUXA unauthenticated RCE in /api/runscripthighCVSS 4EPSS 0.9%
- CVE-2026-43946: frangoteam FUXA authorization bypass in /api/getTagValuehighCVSS 4EPSS 0.6%
- CVE-2026-47718: frangoteam FUXA authentication bypass in protected read APIsmediumCVSS 4EPSS 0.5%
- CVE-2026-47717: FUXA unauthenticated project data disclosure in APIhighCVSS 7.5EPSS 1.4%
- CVE-2025-69971: frangoteam FUXA hardcoded JWT signing secret fallbackhighCVSS 8.1EPSS 2.1%
- CVE-2026-25951: FUXA path traversal sanitization bypassmediumCVSS 4EPSS 1.7%
- CVE-2026-25939: FUXA authorization bypass in scheduler endpointmediumCVSS 4EPSS 0.8%
- CVE-2026-25938: FUXA authentication bypass in Node-RED integrationmediumCVSS 4EPSS 1.3%
- CVE-2026-25752: FUXA unauthenticated remote arbitrary device tag writemediumCVSS 4EPSS 0.7%
- CVE-2026-25895: FUXA path traversal arbitrary file write in upload APImediumCVSS 4EPSS 6.2%
- CVE-2026-25894: FUXA unauthenticated remote code execution via hardcoded JWT secretmediumCVSS 4EPSS 1.2%
- CVE-2026-25751: FUXA unauthenticated exposure of plaintext database credentialsmediumCVSS 4EPSS 0.4%
- CVE-2026-25893: FUXA authentication bypass and remote code execution via heartbeat refresh APImediumCVSS 4EPSS 1.1%
- CVE-2025-69983: FUXA remote code execution in project importlowCVSS 3.1EPSS 0.4%
- CVE-2025-69970: FUXA insecure default authentication configurationmediumCVSS 4EPSS 0.5%
- FUXA hard-coded JWT secret keymediumCVSS 4
- CVE-2025-69981: FUXA unrestricted file upload in API endpointmediumCVSS 4EPSS 0.8%
- frangoteam FUXA hard-coded secret in JWT authenticationhighCVSS 9.8
- CVE-2023-31719: FUXA SQL injection in sign-in endpointlowCVSS 3.1EPSS 26.0%
- CVE-2023-31717: FUXA SQL injection in HTTP POST parameterlowCVSS 3.1EPSS 1.8%
- CVE-2023-31718: FUXA local file inclusion in download endpointlowCVSS 3.1EPSS 1.7%
Most severe fuxa-server (npm) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- frangoteam FUXA hard-coded secret in JWT authenticationhighCVSS 9.8
- CVE-2026-47719: FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE_WEBAPI_REQUEST and…highCVSS 8.2EPSS 0.6%
- CVE-2025-69971: frangoteam FUXA hardcoded JWT signing secret fallbackhighCVSS 8.1EPSS 2.1%
- CVE-2026-47717: FUXA unauthenticated project data disclosure in APIhighCVSS 7.5EPSS 1.4%
- CVE-2026-43947: frangoteam FUXA unauthenticated RCE in /api/runscripthighCVSS 4EPSS 0.9%
- CVE-2026-43946: frangoteam FUXA authorization bypass in /api/getTagValuehighCVSS 4EPSS 0.6%
- CVE-2026-47721: FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, POST /api/scheduler and DELETE…mediumCVSS 6.3EPSS 0.4%
- CVE-2026-47720: FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengine DAQ storage…mediumCVSS 5.3EPSS 0.6%
- CVE-2026-25895: FUXA path traversal arbitrary file write in upload APImediumCVSS 4EPSS 6.2%
- CVE-2026-25951: FUXA path traversal sanitization bypassmediumCVSS 4EPSS 1.7%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 2 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 3 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/fuxa-server.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "fuxa-server (npm) vulnerabilities", https://junglewise.ai/threats/technologies/fuxa-server, 26 September 2026.