Total vulnerabilities in the database
In Home Assistant before 0.57, it is possible to inject JavaScript code into a persistent notification via crafted Markdown text, aka XSS.
CVSS v3:
CVSS v2:
CWEs:
OWASP TOP 10: