Back

HIGH

Stored XSS vulnerability in the Item history/Plain text widget

Published May 6, 2026

Description

The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0.

Affected products

Remediation

Vendor solution

Update the affected components to their respective fixed versions.

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Zabbix
Published May 6, 2026
Updated May 6, 2026
Reserved Jan 19, 2026
CISA Vulnrichment
Updated May 6, 2026
NVD
Status Analyzed
Modified Sep 18, 2026
Red Hat
Severity n/a
Public date n/a