HIGH
Stored XSS vulnerability in the Item history/Plain text widget
Published May 6, 2026
7.3
HIGHCVSS 4.0
EPSS 0.26%
Description
The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0.
Affected products
-
- Version 6.0.0StatusaffectedConstraints<=6.0.44
- Version 7.0.0StatusaffectedConstraints<=7.0.23
- Version 7.4.0StatusaffectedConstraints<=7.4.7
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update the affected components to their respective fixed versions.
Weaknesses (1)
References (1)
- https://support.zabbix.com/browse/ZBX-27760 Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://support.zabbix.com/browse/ZBX-27760 | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Zabbix
Published May 6, 2026
Updated May 6, 2026
Reserved Jan 19, 2026
Link CVE-2026-23928
CISA Vulnrichment
Updated May 6, 2026