Centreon / Centreon Web
56 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-2751 | Blind SQL Injection | CRITICAL | 9.8 | Feb 27, 2026 |
| CVE-2025-12513 | A user with elevated privileges can inject XSS in the Hosts configuration parameters page | MEDIUM | 6.8 | Jan 5, 2026 |
| CVE-2025-12519 | Information disclosure on Administration parameters API endpoint | MEDIUM | 5.3 | Jan 5, 2026 |
| CVE-2025-13056 | A user with elevated privileges can inject XSS in the Administration ACL Menus configuration page | MEDIUM | 6.8 | Jan 5, 2026 |
| CVE-2025-5965 | RCE via the backup feature available only to user with high privilege | HIGH | 7.2 | Jan 5, 2026 |
| CVE-2025-54890 | A user with elevated privileges can inject XSS in the Hostgroups configuration page | MEDIUM | 6.8 | Dec 22, 2025 |
| CVE-2025-10023 | A user with elevated privileges can inject XSS in the Services Meta-services configuration page | MEDIUM | 6.2 | Oct 27, 2025 |
| CVE-2025-8459 | A user with low privileges can inject XSS in the Monitoring Recurrent downtimes page | HIGH | 7.7 | Oct 14, 2025 |
| CVE-2025-8430 | A user with elevated privileges can inject XSS in the Commands Connectors configuration configuration page | MEDIUM | 6.8 | Oct 14, 2025 |
| CVE-2025-8429 | A user with elevated privileges can inject XSS in the ACL Action access configuration page | MEDIUM | 6.8 | Oct 14, 2025 |
| CVE-2025-54893 | A user with elevated privileges can inject XSS in the Hosts templates configuration page | MEDIUM | 6.8 | Oct 14, 2025 |
| CVE-2025-54891 | A user with elevated privileges can inject XSS in the ACL Resource Access configuration page | MEDIUM | 6.8 | Oct 14, 2025 |
| CVE-2025-54892 | A user with elevated privileges can inject XSS in the SNMP traps group configuration page | MEDIUM | 6.8 | Oct 14, 2025 |
| CVE-2025-54889 | A user with elevated privileges can inject XSS in the SNMP traps manufacturer configuration page | MEDIUM | 6.8 | Oct 14, 2025 |
| CVE-2025-5946 | RCE via the poller reload feature available only to user with high privilege | HIGH | 7.2 | Oct 14, 2025 |
| CVE-2025-8428 | XSS found in the HTTP loader widget | MEDIUM | 6.8 | Oct 14, 2025 |
| CVE-2025-6791 | Second order SQL injection available to user with low privilege | HIGH | 8.8 | Aug 22, 2025 |
| CVE-2025-4650 | User with high privileges is able to introduce a SQLi using the Meta Service indicator page | HIGH | 7.2 | Aug 22, 2025 |
| CVE-2025-4649 | ACL are not correctly taken into account in the display of the "event logs" page. This page requiring, high privileges, will display all available logs. | MEDIUM | 4.9 | May 13, 2025 |
| CVE-2025-4648 | A user with elevated privileges can inject XSS by altering the content of a SVG media during the submit request. | HIGH | 8.4 | May 13, 2025 |
| CVE-2025-4647 | A user with elevated privileges can bypass sanitization measures by replacing the content of an existing SVG | HIGH | 8.4 | May 13, 2025 |
| CVE-2025-4646 | A high privilege user is able to create and use a valid admin API token in centreon-web | HIGH | 7.2 | May 13, 2025 |
| CVE-2025-3872 | Privilege escalation by altering payload in contact form | HIGH | 7.2 | Apr 24, 2025 |
| CVE-2024-55573 | An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A user with… | CRITICAL | 9.1 | Jan 23, 2025 |
| CVE-2024-53923 | An issue was discovered in Centreon Web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A user with high priv… | CRITICAL | 9.1 | Jan 23, 2025 |
Showing 1 to 25 of 56 CVEs