VendorsCentreoncentreon_webany version
Vulnerabilities

Centreon Web any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

51CVEs
CVE-2024-32501
A SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.
Published 2024-08-23 · Analyzed
9.8EPSS 0.192
CVE-2026-2751
Blind SQL Injection
Published 2026-02-27 · Analyzed
9.8EPSS 0.005
CVE-2023-51633
Centreon sysName Cross-Site Scripting Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
9.6EPSS 0.011
CVE-2024-55573
An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A user with high privileges is able to inject SQL into the form used to create virtual metrics.
Published 2025-01-23 · Analyzed
9.1EPSS 0.011
CVE-2024-33854
A SQL Injection vulnerability exists in the Graph Template component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.
Published 2024-08-23 · Analyzed
9.1EPSS 0.005
CVE-2024-33852
A SQL Injection vulnerability exists in the Downtime component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.
Published 2024-08-23 · Analyzed
9.1EPSS 0.005
CVE-2024-33853
A SQL Injection vulnerability exists in the Timeperiod component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.
Published 2024-08-23 · Analyzed
9.1EPSS 0.005
CVE-2024-53923
An issue was discovered in Centreon Web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A user with high privileges is able to achieve SQL injection in the form to upload media.
Published 2025-01-23 · Analyzed
9.1EPSS 0.004
CVE-2019-16405
Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code Execution by an administrator who can modify Macro Expression location settings. CVE-2019-16405 and CVE-2019-17501 are similar to one another and may be the same.
Published 2019-11-21 · Modified
9.01 PoCEPSS 0.270
CVE-2024-0637
Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability
Published 2024-04-01 · Analyzed
8.8EPSS 0.723
CVE-2024-5725
Centreon initCurveList SQL Injection Remote Code Execution Vulnerability
Published 2024-08-21 · Analyzed
8.8EPSS 0.474
CVE-2024-5723
Centreon updateServiceHost SQL Injection Remote Code Execution Vulnerability
Published 2024-08-21 · Analyzed
8.8EPSS 0.407
CVE-2019-15298
A problem was found in Centreon Web through 19.04.3. An authenticated command injection is present in the page include/configuration/configObject/traps-mibs/formMibs.php. This page is called from the Centreon administration interface. This is the mibs management feature that contains a file filing form. At the time of submission of a file, the mnftr parameter is sent to the page and is not filtered properly. This allows one to inject Linux commands directly.
Published 2019-11-27 · Modified
8.8EPSS 0.266
CVE-2019-17107
minPlayCommand.php in Centreon Web before 2.8.27 allows authenticated attackers to execute arbitrary code via the command_hostaddress parameter. NOTE: some sources have listed CVE-2019-17017 for this, but that is incorrect.
Published 2019-10-08 · Modified
8.8EPSS 0.036
CVE-2018-21023
getStats.php in Centreon Web before 2.8.28 allows authenticated attackers to execute arbitrary code via the ns_id parameter.
Published 2019-10-08 · Modified
8.8EPSS 0.030
CVE-2019-15300
A problem was found in Centreon Web through 19.04.3. An authenticated SQL injection is present in the page include/Administration/parameters/ldap/xml/ldap_host.php. The arId parameter is not properly filtered before being passed to the SQL query.
Published 2019-11-27 · Modified
8.8EPSS 0.020
CVE-2018-21021
img_gantt.php in Centreon Web before 2.8.27 allows attackers to perform SQL injections via the host_id parameter.
Published 2019-10-08 · Modified
8.8EPSS 0.018
CVE-2018-21022
makeXML_ListServices.php in Centreon Web before 2.8.28 allows attackers to perform SQL injections via the host_id parameter.
Published 2019-10-08 · Modified
8.8EPSS 0.018
CVE-2019-15299
An issue was discovered in Centreon Web through 19.04.3. When a user changes his password on his profile page, the contact_autologin_key field in the database becomes blank when it should be NULL. This makes it possible to partially bypass authentication.
Published 2020-02-24 · Modified
8.8EPSS 0.016
CVE-2024-23119
Centreon insertGraphTemplate SQL Injection Remote Code Execution Vulnerability
Published 2024-04-01 · Analyzed
8.8EPSS 0.014
CVE-2024-39841
A SQL Injection vulnerability exists in the service configuration functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.
Published 2024-08-23 · Analyzed
8.8EPSS 0.011
CVE-2025-6791
Second order SQL injection available to user with low privilege
Published 2025-08-22 · Analyzed
8.8EPSS 0.003
CVE-2025-4647
A user with elevated privileges can bypass sanitization measures by replacing the content of an existing SVG
Published 2025-05-13 · Analyzed
8.4EPSS 0.003
CVE-2025-4648
A user with elevated privileges can inject XSS by altering the content of a SVG media during the submit request.
Published 2025-05-13 · Analyzed
8.4EPSS 0.003
CVE-2025-8459
A user with low privileges can inject XSS in the Monitoring Recurrent downtimes page
Published 2025-10-14 · Analyzed
7.7EPSS 0.002
CVE-2018-21020
In very rare cases, a PHP type juggling vulnerability in centreonAuth.class.php in Centreon Web before 2.8.27 allows attackers to bypass authentication mechanisms in place.
Published 2019-10-08 · Modified
7.5EPSS 0.020
CVE-2024-23115
Centreon updateGroups SQL Injection Remote Code Execution Vulnerability
Published 2024-04-01 · Analyzed
7.2EPSS 0.675
CVE-2024-23116
Centreon updateLCARelation SQL Injection Remote Code Execution Vulnerability
Published 2024-04-01 · Analyzed
7.2EPSS 0.534
CVE-2024-23117
Centreon updateContactServiceCommands SQL Injection Remote Code Execution Vulnerability
Published 2024-04-01 · Analyzed
7.2EPSS 0.534
CVE-2024-23118
Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability
Published 2024-04-01 · Analyzed
7.2EPSS 0.534
CVE-2025-5965
RCE via the backup feature available only to user with high privilege
Published 2026-01-05 · Analyzed
7.2EPSS 0.286
CVE-2025-5946
RCE via the poller reload feature available only to user with high privilege
Published 2025-10-14 · Analyzed
7.2EPSS 0.135
CVE-2025-4646
A high privilege user is able to create and use a valid admin API token in centreon-web
Published 2025-05-13 · Analyzed
7.2EPSS 0.004
CVE-2025-4650
User with high privileges is able to introduce a SQLi using the Meta Service indicator page
Published 2025-08-22 · Analyzed
7.2EPSS 0.004
CVE-2025-3872
Privilege escalation by altering payload in contact form
Published 2025-04-24 · Analyzed
7.2EPSS 0.004
CVE-2025-54889
A user with elevated privileges can inject XSS in the SNMP traps manufacturer configuration page
Published 2025-10-14 · Analyzed
6.8EPSS 0.003
CVE-2025-54891
A user with elevated privileges can inject XSS in the ACL Resource Access configuration page
Published 2025-10-14 · Analyzed
6.8EPSS 0.003
CVE-2025-54892
A user with elevated privileges can inject XSS in the SNMP traps group configuration page
Published 2025-10-14 · Analyzed
6.8EPSS 0.003
CVE-2025-8428
XSS found in the HTTP loader widget
Published 2025-10-14 · Analyzed
6.8EPSS 0.002
CVE-2025-8430
A user with elevated privileges can inject XSS in the Commands Connectors configuration configuration page
Published 2025-10-14 · Analyzed
6.8EPSS 0.002
1 / 2Next →