VendorsCentreoncentreon_webany version
Vulnerabilities

Centreon Web any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

51CVEs
CVE-2025-8429
A user with elevated privileges can inject XSS in the ACL Action access configuration page
Published 2025-10-14 · Analyzed
6.8EPSS 0.002
CVE-2025-54893
A user with elevated privileges can inject XSS in the Hosts templates configuration page
Published 2025-10-14 · Analyzed
6.8EPSS 0.002
CVE-2025-54890
A user with elevated privileges can inject XSS in the Hostgroups configuration page
Published 2025-12-22 · Analyzed
6.8EPSS 0.002
CVE-2025-13056
A user with elevated privileges can inject XSS in the Administration ACL Menus configuration page
Published 2026-01-05 · Analyzed
6.8EPSS 0.002
CVE-2025-12513
A user with elevated privileges can inject XSS in the Hosts configuration parameters page
Published 2026-01-05 · Analyzed
6.8EPSS 0.002
CVE-2019-17106
In Centreon Web through 2.8.29, disclosure of external components' passwords allows authenticated attackers to move laterally to external components.
Published 2019-10-08 · Modified
6.5EPSS 0.011
CVE-2025-10023
A user with elevated privileges can inject XSS in the Services Meta-services configuration page
Published 2025-10-27 · Analyzed
6.2EPSS 0.002
CVE-2019-17108
Local file inclusion in brokerPerformance.php in Centreon Web before 2.8.28 allows attackers to disclose information or perform a stored XSS attack on a user.
Published 2019-10-08 · Modified
6.1EPSS 0.012
CVE-2019-17105
The token generator in index.php in Centreon Web before 2.8.27 is predictable.
Published 2019-10-08 · Modified
5.3EPSS 0.016
CVE-2025-12519
Information disclosure on Administration parameters API endpoint
Published 2026-01-05 · Analyzed
5.3EPSS 0.002
CVE-2025-4649
ACL are not correctly taken into account in the display of the "event logs" page. This page requiring, high privileges, will display all available logs.
Published 2025-05-13 · Analyzed
4.9EPSS 0.004
← Prev2 / 2