VendorsCentreoncentreon_weball versions
Vulnerabilities

Centreon Web

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

56CVEs
CVE-2025-54892
A user with elevated privileges can inject XSS in the SNMP traps group configuration page
Published 2025-10-14 · Analyzed
6.8EPSS 0.003
CVE-2025-8428
XSS found in the HTTP loader widget
Published 2025-10-14 · Analyzed
6.8EPSS 0.002
CVE-2025-54893
A user with elevated privileges can inject XSS in the Hosts templates configuration page
Published 2025-10-14 · Analyzed
6.8EPSS 0.002
CVE-2025-8429
A user with elevated privileges can inject XSS in the ACL Action access configuration page
Published 2025-10-14 · Analyzed
6.8EPSS 0.002
CVE-2025-8430
A user with elevated privileges can inject XSS in the Commands Connectors configuration configuration page
Published 2025-10-14 · Analyzed
6.8EPSS 0.002
CVE-2025-54890
A user with elevated privileges can inject XSS in the Hostgroups configuration page
Published 2025-12-22 · Analyzed
6.8EPSS 0.002
CVE-2025-13056
A user with elevated privileges can inject XSS in the Administration ACL Menus configuration page
Published 2026-01-05 · Analyzed
6.8EPSS 0.002
CVE-2025-12513
A user with elevated privileges can inject XSS in the Hosts configuration parameters page
Published 2026-01-05 · Analyzed
6.8EPSS 0.002
CVE-2021-26804
Insecure Permissions in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 allows remote attackers to bypass validation by changing any file extension to ".gif", then uploading it in the "Administration/ Parameters/ Images" section of the application.
Published 2021-05-04 · Modified
6.5EPSS 0.012
CVE-2019-17106
In Centreon Web through 2.8.29, disclosure of external components' passwords allows authenticated attackers to move laterally to external components.
Published 2019-10-08 · Modified
6.5EPSS 0.011
CVE-2025-10023
A user with elevated privileges can inject XSS in the Services Meta-services configuration page
Published 2025-10-27 · Analyzed
6.2EPSS 0.002
CVE-2019-17108
Local file inclusion in brokerPerformance.php in Centreon Web before 2.8.28 allows attackers to disclose information or perform a stored XSS attack on a user.
Published 2019-10-08 · Modified
6.1EPSS 0.012
CVE-2018-11588
Centreon 3.4.6 including Centreon Web 2.8.23 is vulnerable to an authenticated user injecting a payload into the username or command description, resulting in stored XSS. This is related to www/include/core/menu/menu.php and www/include/configuration/configObject/command/formArguments.php.
Published 2018-06-25 · Modified
5.4EPSS 0.011
CVE-2019-17105
The token generator in index.php in Centreon Web before 2.8.27 is predictable.
Published 2019-10-08 · Modified
5.3EPSS 0.016
CVE-2025-12519
Information disclosure on Administration parameters API endpoint
Published 2026-01-05 · Analyzed
5.3EPSS 0.002
CVE-2025-4649
ACL are not correctly taken into account in the display of the "event logs" page. This page requiring, high privileges, will display all available logs.
Published 2025-05-13 · Analyzed
4.9EPSS 0.004
← Prev2 / 2