Zabbix / Frontend
14 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-49643 | Frontend DoS vulnerability due to asymmetric resource consumption | MEDIUM | 6.0 | Dec 1, 2025 |
| CVE-2025-27232 | Frontend arbitrary file read in oauth.authorize action | MEDIUM | 6.8 | Dec 1, 2025 |
| CVE-2024-42330 | JS - Internal strings in HTTP headers | CRITICAL | 9.1 | Nov 27, 2024 |
| CVE-2023-32725 | Leak of zbx_session cookie when using a scheduled report that includes a dashboard with a URL widget. | CRITICAL | 9.6 | Dec 18, 2023 |
| CVE-2023-30958 | DOM XSS in Developer mode dashboard via redirect GET parameter | MEDIUM | 6.1 | Aug 3, 2023 |
| CVE-2023-29457 | Insufficient validation of Action form input fields | MEDIUM | 6.3 | Jul 13, 2023 |
| CVE-2023-29456 | Inefficient URL schema validation | MEDIUM | 5.7 | Jul 13, 2023 |
| CVE-2023-29455 | Reflected XSS in several fields of graph form | MEDIUM | 6.1 | Jul 13, 2023 |
| CVE-2023-29454 | Persistent XSS in the user form | MEDIUM | 5.4 | Jul 13, 2023 |
| CVE-2022-43515 | X-Forwarded-For header is active by default causes access to Zabbix sites in maintenance mode | CRITICAL | 9.8 | Dec 12, 2022 |
| CVE-2022-40626 | Reflected XSS in the backurl parameter of Zabbix Frontend | MEDIUM | 6.1 | Sep 14, 2022 |
| CVE-2022-35230 | Reflected XSS in graphs page of Zabbix Frontend | MEDIUM | 5.4 | Jul 6, 2022 |
| CVE-2022-35229 | Reflected XSS in discovery page of Zabbix Frontend | MEDIUM | 5.4 | Jul 6, 2022 |
| CVE-2022-24919 | Reflected XSS in graph configuration window of Zabbix Frontend | MEDIUM | 4.4 | Mar 9, 2022 |
| CVE-2022-24918 | Reflected XSS in item configuration window of Zabbix Frontend | MEDIUM | 4.4 | Mar 9, 2022 |
| CVE-2022-24917 | Reflected XSS in service configuration window of Zabbix Frontend | MEDIUM | 4.4 | Mar 9, 2022 |
| CVE-2022-24349 | Reflected XSS in action configuration window of Zabbix Frontend | MEDIUM | 4.6 | Mar 9, 2022 |
| CVE-2022-23134 KEV | Possible view of the setup pages by unauthenticated users if config file already exists | MEDIUM | 5.3 | Jan 13, 2022 |
| CVE-2022-23133 | Stored XSS in host groups configuration window in Zabbix Frontend | MEDIUM | 6.3 | Jan 13, 2022 |
| CVE-2022-23131 KEV | Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML | CRITICAL | 9.8 | Jan 13, 2022 |
Showing 1 to 14 of 14 CVEs