← Back

Rainmachine Web Application

rainmachine_web_application

Vendor: Rainmachine • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Rainmachine
1Rainmachine Web Application
Jun 17, 2026
Nov 1, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A missing X-Frame-Options header in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application could be used by a remote attacker for clickjacking, as demonstrated by triggering an API page...Show more
A missing X-Frame-Options header in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application could be used by a remote attacker for clickjacking, as demonstrated by triggering an API page request.Show less
1Rainmachine
1Rainmachine Web Application
Jun 17, 2026
Nov 1, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A Cross Site Request Forgery (CSRF) vulnerability in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application allows an attacker to control the RainMachine device via the REST API.
1Rainmachine
1Rainmachine Web Application
Jun 17, 2026
Nov 1, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A persistent Cross Site Scripting (XSS) vulnerability in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application allows an attacker to inject arbitrary JavaScript via the REST API.