<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — OpenPLC</title><description>Actively exploited vulnerabilities affecting OpenPLC products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/openplc.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2021-26828 — OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability</title><link>https://wildfortech.com/security#CVE-2021-26828</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2021-26828</guid><description>This vulnerability in OpenPLC&apos;s ScadaBR allows any authenticated user to upload and execute arbitrary JSP files through a specific endpoint. In industrial control and SCADA environments, this is especially serious: an attacker with even low-level credentials can effectively take full control of the server, potentially manipulating or disrupting industrial processes. The fact that it requires authentication provides only a thin barrier, since credentials can be stolen, guessed, or obtained through phishing.</description><pubDate>Wed, 03 Dec 2025 00:00:00 GMT</pubDate><category>OpenPLC</category><category>ScadaBR</category></item><item><title>CVE-2021-26829 — OpenPLC ScadaBR Cross-site Scripting Vulnerability</title><link>https://wildfortech.com/security#CVE-2021-26829</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2021-26829</guid><description>This cross-site scripting (XSS) vulnerability in OpenPLC&apos;s ScadaBR affects the system_settings.shtm page, a component used in industrial control and SCADA environments. An attacker who can deliver a malicious script through this endpoint could potentially hijack authenticated user sessions, steal credentials, or manipulate what operators see on their HMI dashboards. Because SCADA systems often control physical processes, compromised operator interfaces carry risks beyond typical IT environments.</description><pubDate>Fri, 28 Nov 2025 00:00:00 GMT</pubDate><category>OpenPLC</category><category>ScadaBR</category></item></channel></rss>