Centreon / Web
7 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-2750 | Command Injection via CLAPI generatetraps | CRITICAL | 9.8 | Feb 27, 2026 |
| CVE-2025-6791 | Second order SQL injection available to user with low privilege | HIGH | 8.8 | Aug 22, 2025 |
| CVE-2025-4650 | User with high privileges is able to introduce a SQLi using the Meta Service indicator page | HIGH | 7.2 | Aug 22, 2025 |
| CVE-2025-4649 | ACL are not correctly taken into account in the display of the "event logs" page. This page requiring, high privileges, will display all available logs. | MEDIUM | 4.9 | May 13, 2025 |
| CVE-2025-4648 | A user with elevated privileges can inject XSS by altering the content of a SVG media during the submit request. | HIGH | 8.4 | May 13, 2025 |
| CVE-2025-4647 | A user with elevated privileges can bypass sanitization measures by replacing the content of an existing SVG | HIGH | 8.4 | May 13, 2025 |
| CVE-2025-4646 | A high privilege user is able to create and use a valid admin API token in centreon-web | HIGH | 7.2 | May 13, 2025 |
Showing 1 to 7 of 7 CVEs